The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.11.1. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token.
Metrics
Affected Vendors & Products
References
History
Wed, 19 Feb 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | ProfilePress - Pro <= 4.11.1 - Authentication Bypass | ProfilePress - Pro <= 4.11.1 - Authentication Bypass via WordPress.com OAuth provider |
Fri, 25 Oct 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Properfraction
Properfraction profilepress |
|
CPEs | cpe:2.3:a:properfraction:profilepress:*:*:*:*:pro:wordpress:*:* | |
Vendors & Products |
Properfraction
Properfraction profilepress |
Wed, 23 Oct 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Profilepress
Profilepress profilepress |
|
CPEs | cpe:2.3:a:profilepress:profilepress:*:*:*:*:pro:wordpress:*:* | |
Vendors & Products |
Profilepressteam
Profilepressteam profilepressteam |
Profilepress
Profilepress profilepress |
Wed, 23 Oct 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Profilepressteam
Profilepressteam profilepressteam |
|
Weaknesses | CWE-276 | |
CPEs | cpe:2.3:a:profilepressteam:profilepressteam:*:*:*:*:*:*:*:* | |
Vendors & Products |
Profilepressteam
Profilepressteam profilepressteam |
|
Metrics |
ssvc
|
Wed, 23 Oct 2024 07:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.11.1. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email and the user does not have an already-existing account for the service returning the token. | |
Title | ProfilePress - Pro <= 4.11.1 - Authentication Bypass | |
Weaknesses | CWE-287 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-02-19T17:41:44.129Z
Reserved: 2024-10-14T18:32:44.474Z
Link: CVE-2024-9947

Updated: 2024-10-23T13:20:19.668Z

Status : Analyzed
Published: 2024-10-23T07:15:04.560
Modified: 2024-10-25T16:53:12.867
Link: CVE-2024-9947

No data.