A HIGH severity vulnerability was found in Paid Member Subscriptions plugin version 3.0.7 and earlier. The vulnerability is an Insecure Direct Object References (IDOR) issue, which could allow attackers to access sensitive data. This issue affects users of Paid Member Subscriptions plugin version 3.0.7 and earlier. The vulnerability allows unauthenticated attackers to access sensitive data by manipulating [truncated]
A vulnerability was found in Cozmoslabs User Profile Picture metronet-profile-picture. It has been classified as problematic. Affected is an unknown function of the component User-Controlled Key Handler. The manipulation leads to authorization bypass. The issue affects User Profile Picture: from n/a through <= 2.6.3. This vulnerability allows attackers to bypass authorization due to incorrectly configured [truncated]
CVE-2026-42385 is a high-severity Unauthenticated Cross Site Scripting (XSS) vulnerability in Profile Builder Pro versions <= 3.15.0. The vulnerability has a CVSS score of 7.1 and is considered HIGH. It was published on 2026-06-17T13:20:40.067Z and last modified on 2026-06-17T15:16:50.517Z. Users of Profile Builder Pro should update to a patched version to prevent exploitation. The vulnerability allows at [truncated]
CVE-2026-39514 is a HIGH severity Unauthenticated Cross Site Scripting (XSS) vulnerability affecting Paid Member Subscriptions plugin versions <= 2.17.3. The vulnerability has a CVSS score of 7.1 and was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-39514). The vulnerability was reported by Patchstack.