PatchSiren

properfraction CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH properfraction CVE published 2026-07-17

CVE-2026-13352

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress has an Arbitrary File Upload vulnerability in all versions up to, and including, 4.16.18. This is due to an unconditional registration of an upload_mimes filter that adds executable file extensions to the global WordPress MIME allowlist without scoping it to digita [truncated]

CRITICAL properfraction CVE published 2026-07-13

CVE-2026-57813

A critical vulnerability was found in the MailOptin plugin for WordPress, affecting versions from n/a through 1.2.77.3. This Incorrect Privilege Assignment vulnerability allows for Privilege Escalation, with a CVSS score of 9.8. The issue has a high impact on the confidentiality, integrity, and availability of the affected systems. Administrators and users of the MailOptin plugin for WordPress should be a [truncated]

MEDIUM properfraction CVE published 2026-06-15

CVE-2026-41556

A Subscriber Cross Site Scripting (XSS) vulnerability was discovered in ProfilePress plugin versions up to 4.16.13. The vulnerability has been assigned a CVSS score of 6.5, indicating a medium severity level.

MEDIUM properfraction CVE published 2026-04-04

CVE-2026-3309

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.11. This is due to the plugin allowing user-supplied billing field values from the checkout process to be interpolated into shortcode template strings that are subsequently pr [truncated]

HIGH properfraction CVE published 2026-04-04

CVE-2026-3445

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to unauthorized membership payment bypass in all versions up to, and including, 4.16.11. This vulnerability allows authenticated attackers, with subscriber level access and above, to reference another user's active subscription during checkout to mani [truncated]