ProfilePress is a popular WordPress plugin that provides user profile and membership management features. However, CVE-2024-13119 highlights a critical Stored Cross-Site Scripting (XSS) vulnerability that allows attackers to inject malicious JavaScript into the plugin’s settings. This vulnerability can be exploited by attackers with editor-level access to inject JavaScript into the “Title” field in the Member Directory settings. When the settings are saved, the malicious code is stored in the WordPress database and executed when the directory is rendered. This flaw enables attackers to create a backdoor, potentially giving them full control of the site. With over 200,000 active installations, this vulnerability poses a serious risk to websites using ProfilePress.
CVE-2024-13119 – ProfilePress – Stored XSS to JS Backdoor Creation – POC
