Cross Site Scripting Vulnerability in ProfilePress by WordPress
CVE-2026-41556
6.5MEDIUM
What is CVE-2026-41556?
The ProfilePress plugin for WordPress is susceptible to a Cross Site Scripting (XSS) vulnerability. This affects versions up to 4.16.13, allowing an attacker to inject malicious scripts into the application, potentially compromising user data and session integrity. Users are urged to update to the latest version to protect against these types of attacks.
Affected Version(s)
ProfilePress <= 4.16.13