
WP Register Profile With Shortcode Security & Risk Analysis
wordpress.org/plugins/wp-register-profile-with-shortcodeThis is a simple registration form in the widget. just install the plugin and add the register widget in the sidebar. Thats it. :)
Is WP Register Profile With Shortcode Safe to Use in 2026?
Mostly Safe
Score 71/100WP Register Profile With Shortcode is generally safe to use. 4 past CVEs were resolved. Keep it updated.
The plugin "wp-register-profile-with-shortcode" v3.6.3 exhibits a mixed security posture. While it demonstrates good practices by exclusively using prepared statements for SQL queries and appears to have no directly exploitable unsanitized taint flows in the analyzed code, several concerning areas remain. The significant number of known CVEs, with one still unpatched, including a high-severity vulnerability, points to a recurring history of security weaknesses. The common vulnerability types also suggest potential issues with input validation and authorization that could lead to data exposure, unauthorized actions, or cross-site scripting. The lack of capability checks on its shortcodes, despite them representing the primary attack surface, is a significant concern, as it implies that any user, regardless of role, could potentially trigger functionality that might have security implications. The output escaping, while partially implemented, is not fully robust, leaving room for potential cross-site scripting if certain outputs are not correctly handled.
Key Concerns
- Unpatched High Severity CVE detected
- No capability checks on shortcodes
- Output escaping not fully robust (66% proper)
- History of 4 known CVEs
WP Register Profile With Shortcode Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
WP Register Profile With Shortcode <= 3.6.2 - Authenticated (Contributor+) Sensitive Information Exposure
WP Register Profile With Shortcode <= 3.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Register Profile With Shortcode <= 3.5.9 - Cross-Site Request Forgery to User Password Reset
WP Register Profile With Shortcode <= 3.5.7 - Authenticated (Administrator+) Stored Cross-Site Scripting
WP Register Profile With Shortcode Code Analysis
Output Escaping
Data Flow Analysis
WP Register Profile With Shortcode Attack Surface
Shortcodes 4
WordPress Hooks 14
Maintenance & Trust
WP Register Profile With Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
WP Register Profile With Shortcode Alternatives
Login Logout Menu
login-logout-menu
Login Logout Menu is a handy plugin which allows you to add login, logout, register and profile menu items in your selected menu.
Frontend Dashboard
frontend-dashboard
Frontend Dashboard is bundled with huge list of custom features which can easily customise the User profile, Posts, Login, Register, Custom roles.
WP Frontend Profile
wp-front-end-profile
WP Frontend Profile allows users to edit/view their profile and register/login without going into the dashboard to do so.
Get Login Plugin
get-log-in
Adds 'Log In', 'Log Out', 'Register' and 'My Profile' respectively to navigation listed using "wp_list_pa …
Astra Widgets
astra-widgets
Quickest solution to add widgets like Address, Social Profiles and List icons on a website built with Astra.
WP Register Profile With Shortcode Developer Profile
9 plugins · 8K total installs
How We Detect WP Register Profile With Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-register-profile-with-shortcode/css/style_register_widget_admin.css/wp-content/plugins/wp-register-profile-with-shortcode/js/ap.cookie.js/wp-content/plugins/wp-register-profile-with-shortcode/js/ap-tabs.js/wp-content/plugins/wp-register-profile-with-shortcode/css/style_register_widget.css/wp-content/plugins/wp-register-profile-with-shortcode/js/jquery.validate.min.js/wp-content/plugins/wp-register-profile-with-shortcode/js/additional-methods.js/wp-content/plugins/wp-register-profile-with-shortcode/js/ap.cookie.js/wp-content/plugins/wp-register-profile-with-shortcode/js/ap-tabs.js/wp-content/plugins/wp-register-profile-with-shortcode/js/jquery.validate.min.js/wp-content/plugins/wp-register-profile-with-shortcode/js/additional-methods.jsHTML / DOM Fingerprints
reg-form-group<!--
/* |||||
/* <(`0_0`)>
/* ()(afo)()
/* ()-()
*/
-->name="profile"id="profile"action=""value="wprp_user_edit_profile"name="wprp_user_edit_profile"name="wprp_5q5rt78"+1 more[rp_register_widget][rp_profile_edit][rp_update_password][rp_user_data]