S4E just found a high-severity finding from [ai] pa ssl inspection control
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2021-24522

6.1
CVSS
Description

The User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.11's widget for tabbed login/register was not properly escaped and could be used in an XSS attack which could lead to wp-admin access. Further, the plugin in several places assigned $_POST as $_GET which meant that in some cases this could be replicated with just $_GET parameters and no need for $_POST values.

Attack Vector
-
Privileges Req.
-
User Interaction
-
user registration, user profile, login & membership – profilepress (formerly wp user avatar)
Updated Sep 26, 2026View on NVD →
S4E scanner

CVE history: user registration, user profile, login & membership – profilepress (formerly wp user avatar)

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →