ProfilePress (WordPress) Update
2484Warning Date
Severity Level
Warning Number
Target Sector
29 June, 2021
● Critical
2021-3114
All
Description:
Wordfence has released security update to address multiple vulnerabilities in the following plugin:
- User Registration, User Profiles, Login & Membership – ProfilePress (Formerly WP User Avatar)
- 3.1 – 3.1.3
Threats:
Attacker could exploit this vulnerability by doing the following:
- Privilege escalation
- Arbitrary code execution
Best practice and Recommendations:
The CERT team encourages users to review Wordfence security advisory and apply the necessary update: