Impact
The ProfilePress plugin includes a reflected cross‑site scripting flaw triggered by the ppress_billing_address filename parameter. Unsanitized input in a POST request allows an attacker to embed arbitrary scripts that the victim’s browser will execute when they click a crafted link, leading to potential defacement, phishing, or session hijacking.
Affected Systems
All WordPress sites that have the Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress installed in versions 4.17.4 or earlier are susceptible. The vulnerability is specific to pages hosting the ProfilePress Tabbed Widget where the file upload field is present.
Risk and Exploitability
The severity is moderate with a CVSS score of 6.1. No exploit probability data is available from EPSS and the flaw is not listed in the CISA KEV catalog. The attack requires no authentication and can be carried out by a malicious link that the victim clicks; if the user is not prevented from visiting such a link, the malicious script will run in their browser session. Because the vector is user interaction based, the exploitability is limited to social engineering or phishing, but the impact on the compromised user can be significant.
OpenCVE Enrichment