CVE-2024-13120
ProfilePress < 4.15.20 - Admin+ Stored XSS
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.15.19 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2025-01-01 CVE Reserved
- 2025-01-23 CVE Published
- 2025-03-22 CVE Updated
- 2025-03-22 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/5b70798c-c30d-42e6-ac72-821c5568b9b5 | 2025-03-22 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Unknown Search vendor "Unknown" | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Search vendor "Unknown" for product "Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content" | < 4.15.20 Search vendor "Unknown" for product "Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content" and version " < 4.15.20" | en |
Affected
|