The ProfilePress plugin for WordPress (<= 4.17.4) is vulnerable to sensitive information exposure, allowing authenticated and unauthenticated attackers to extract user PII via crafted shortcode parameters.
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
web-application-vulnerability
wordpress
cve
2t
1c