CVE-2021-24522
Published: Aug 9, 2021
Modified: Aug 3, 2024
Description
The User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.11's widget for tabbed login/register was not properly escaped and could be used in an XSS attack which could lead to wp-admin access. Further, the plugin in several places assigned $_POST as $_GET which meant that in some cases this could be replicated with just $_GET parameters and no need for $_POST values.
| Vendor | Product | Versions |
|---|---|---|
Unknown | User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) | affected 3.1.11 - < 3.1.11 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now