Security Advisory

CVE-2024-6668

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-05-15 20:07:08
Last updated 2025-05-20 19:24:18
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The ProfilePro WordPress plugin through 1.3 does not sanitise and escape some parameters and lacks proper access controls, which could allow users with a role as low as subscriber to perform Cross-Site Scripting attacks