plugin

Profilegrid User Profiles Groups And Communities Vulnerabilities

112 known security issues reported for the Profilegrid User Profiles Groups And Communities WordPress plugin. Most recent disclosed Aug 2, 2026.

4 critical 8 high 52 medium

Running Profilegrid User Profiles Groups And Communities on your site? Check whether your installed version is affected.

Scan your site free

ProfileGrid – User Profiles, Groups and Communities < 5.9.9.8 - Authenticated (Subscriber+) Insecure Direct Object Reference

medium

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to 5.9.9.8 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthori...

CVSS:
4.3
Affected:
up to 5.9.9.8
Fixed in:
5.9.9.8
Disclosed:
Aug 2, 2026

CVE-2026-16291 on NVD →

ProfileGrid <= 5.0.0.0 - Missing Authorization

medium

The ProfileGrid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.0.0.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 5.0.0.0
Fixed in:
6.0.0.0
Disclosed:
Jul 30, 2026

CVE-2026-16290 on NVD →

ProfileGrid <= 5.0.0.0 - Missing Authorization

medium

The ProfileGrid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.0.0.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 5.0.0.0
Fixed in:
6.0.0.0
Disclosed:
Jul 24, 2026

CVE-2026-16289 on NVD →

ProfileGrid – User Profiles, Groups and Communities < 5.9.9.8 - Unauthenticated Group Registration Bypass

medium

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Registration Bypass in all versions up to 5.9.9.8 (exclusive). This makes it possible for unauthenticated attackers to register in groups that they should not be able to.

CVSS:
6.5
Affected:
up to 5.9.9.8
Fixed in:
5.9.9.8
Disclosed:
Jul 10, 2026

CVE-2026-12687 on NVD →

ProfileGrid – User Profiles, Groups and Communities <= 5.9.9.6 - Unauthenticated Privilege Escalation via Password Reset

critical

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.9.9.6. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it possible...

CVSS:
9.8
Affected:
up to 5.9.9.6
Fixed in:
5.9.9.7
Disclosed:
Jul 8, 2026

CVE-2026-57697 on NVD →

ProfileGrid <= 5.9.9.6 - Unauthenticated Payment Bypass

medium

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Payment Bypass in all versions up to, and including, 5.9.9.6. This makes it possible for unauthenticated attackers to bypass payments.

CVSS:
5.3
Affected:
up to 5.9.9.6
Fixed in:
5.9.9.7
Disclosed:
Jul 3, 2026

CVE-2026-12688 on NVD →

ProfileGrid <= 5.9.9.6 - Missing Authorization

medium

The ProfileGrid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.9.9.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 5.9.9.6
Fixed in:
5.9.9.7
Disclosed:
Jul 3, 2026

CVE-2026-12689 on NVD →

ProfileGrid <= 5.9.9.6 - Missing Authorization

medium

The ProfileGrid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.9.9.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 5.9.9.6
Fixed in:
5.9.9.7
Disclosed:
Jul 3, 2026

CVE-2026-12690 on NVD →

ProfileGrid – User Profiles, Groups and Communities <= 5.9.9.8 - Cross-Site Request Forgery

medium

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.9.9.8. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action v...

CVSS:
4.3
Affected:
up to 5.9.9.8
Fix:
No patched version reported
Disclosed:
Jul 2, 2026

CVE-2026-57759 on NVD →

ProfileGrid - User Profiles, Groups and Communities <= 5.9.9.5 - Unauthenticated Privilege Escalation via Email Overwrite

critical

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.9.9.5. This is due to the plugin not validating a `user_login` on registration forms that don't contain this parameter, and not properly handlin...

CVSS:
9.8
Affected:
up to 5.9.9.5
Fixed in:
5.9.9.6
Disclosed:
Jun 29, 2026

CVE-2026-12073 on NVD →

ProfileGrid <= 5.9.9.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Message Content

medium

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pm_author_message' parameter in the pm_send_message_to_author function in all versions up to, and including, 5.9.9.2 due to insufficient input sanitization and output escaping. This makes i...

CVSS:
6.4
Affected:
up to 5.9.9.2
Fixed in:
5.9.9.3
Disclosed:
Jun 22, 2026

CVE-2026-4610 on NVD →

ProfileGrid <= 5.9.8.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Group Joining

high

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the pm_invite_user function in all versions up to, and including, 5.9.8.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to...

CVSS:
7.1
Affected:
up to 5.9.8.4
Fixed in:
5.9.8.5
Disclosed:
May 12, 2026

CVE-2026-4609 on NVD →

ProfileGrid <= 5.9.8.4 - Authenticated (Subscriber+) SQL Injection via 'rid' Parameter

medium

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind SQL Injection via the 'rid' parameter in all versions up to, and including, 5.9.8.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it...

CVSS:
6.5
Affected:
up to 5.9.8.4
Fixed in:
5.9.8.5
Disclosed:
May 12, 2026

CVE-2026-4608 on NVD →

ProfileGrid <= 5.9.8.4 - Missing Authorization to Authenticated (Subscriber+) Group Settings Modification

medium

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.9.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action via the pm_set_group_order, pm_set_group_items, and pm_set_fie...

CVSS:
4.3
Affected:
up to 5.9.8.4
Fixed in:
5.9.8.5
Disclosed:
May 12, 2026

CVE-2026-4607 on NVD →

ProfileGrid – User Profiles, Groups and Communities <= 5.9.8.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.9.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to i...

CVSS:
6.4
Affected:
up to 5.9.8.1
Fixed in:
5.9.8.2
Disclosed:
Mar 23, 2026

CVE-2026-25417 on NVD →

ProfileGrid - Missing Authorization to Authenticated (Subscriber+) Arbitrary Message Deletion vulnerability

medium

Missing Authorization to Authenticated (Subscriber+) Arbitrary Message Deletion vulnerability

CVSS:
4.3
Affected:
up to 5.9.8.1
Fixed in:
5.9.8.2
Disclosed:
Mar 7, 2026

ProfileGrid <= 5.9.8.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Message Deletion

medium

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized message deletion due to a missing capability check on the pg_delete_msg() function in all versions up to, and including, 5.9.8.1. This is due to the function not verifying that the requesting user has permission t...

CVSS:
4.3
Affected:
up to 5.9.8.1
Fixed in:
5.9.8.2
Disclosed:
Mar 6, 2026

CVE-2026-2488 on NVD →

ProfileGrid <= 5.9.8.2 - Cross-Site Request Forgery to Group Membership Request Approval/Denial

medium

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.9.8.2. This is due to missing nonce validation on the membership request management page (approve and decline actions). This makes it possible for unauthentica...

CVSS:
4.3
Affected:
up to 5.9.8.2
Fixed in:
5.9.8.3
Disclosed:
Mar 6, 2026

CVE-2026-2494 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.9.7.3

unknown

[en] The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized user suspension due to a missing capability check on the pm_deactivate_user_from_group() function in all versions up to, and including, 5.9.7.2. This makes it possible for authenticated attackers, with Subscr...

Affected:
up to 5.9.7.3
Fixed in:
5.9.7.3
Disclosed:
Feb 5, 2026

CVE-2025-13416 on NVD →

ProfileGrid <= 5.9.7.2 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Profile and Cover Image Modification

medium

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.7.2 via the 'pm_upload_image' and 'pm_upload_cover_image' AJAX actions. This is due to the update_user_meta() function being called outside of the user...

CVSS:
5.3
Affected:
up to 5.9.7.2
Fixed in:
5.9.7.3
Disclosed:
Feb 4, 2026

CVE-2026-1271 on NVD →

ProfileGrid – User Profiles, Groups and Communities <= 5.9.7.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Suspension

medium

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized user suspension due to a missing capability check on the pm_deactivate_user_from_group() function in all versions up to, and including, 5.9.7.2. This makes it possible for authenticated attackers, with Subscriber-...

CVSS:
4.3
Affected:
up to 5.9.7.2
Fixed in:
5.9.7.3
Disclosed:
Feb 4, 2026

CVE-2025-13416 on NVD →

ProfileGrid – User Profiles, Groups and Communities <= 5.9.5.7 - Reflected Cross-Site Scripting

medium

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 5.9.5.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in p...

CVSS:
6.1
Affected:
up to 5.9.5.7
Fixed in:
5.9.5.8
Disclosed:
Sep 1, 2025

CVE-2025-4957 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.9.5.4

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid allows Blind SQL Injection. This issue affects ProfileGrid : from n/a through 5.9.5.3.

Affected:
up to 5.9.5.4
Fixed in:
5.9.5.4
Disclosed:
Aug 14, 2025

CVE-2025-49033 on NVD →

ProfileGrid <= 5.9.5.3 - Authenticated (Subscriber+) SQL Injection

medium

The ProfileGrid plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.9.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and a...

CVSS:
6.5
Affected:
up to 5.9.5.3
Fixed in:
5.9.5.4
Disclosed:
Jul 24, 2025

CVE-2025-49033 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.9.5.3

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid allows SQL Injection. This issue affects ProfileGrid : from n/a through 5.9.5.2.

Affected:
up to 5.9.5.3
Fixed in:
5.9.5.3
Disclosed:
Jul 16, 2025

CVE-2025-49876 on NVD →

ProfileGrid – User Profiles, Groups and Communities <= 5.9.5.4 - Reflected Cross-Site Scripting via 'pm_get_messenger_notification' function

medium

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘pm_get_messenger_notification’ function in all versions up to, and including, 5.9.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticat...

CVSS:
6.1
Affected:
up to 5.9.5.4
Fixed in:
5.9.5.5
Disclosed:
Jul 15, 2025

CVE-2025-6977 on NVD →

ProfileGrid <= 5.9.5.2 - Authenticated (Subscriber+) SQL Injection

medium

The ProfileGrid plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.9.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and a...

CVSS:
6.5
Affected:
up to 5.9.5.2
Fixed in:
5.9.5.3
Disclosed:
Jul 10, 2025

CVE-2025-49876 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.9.5.3

unknown

[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Metagauss ProfileGrid allows Retrieve Embedded Sensitive Data. This issue affects ProfileGrid : from n/a through 5.9.5.2.

Affected:
up to 5.9.5.3
Fixed in:
5.9.5.3
Disclosed:
Jun 20, 2025

CVE-2025-52719 on NVD →

ProfileGrid <= 5.9.5.2 - Authenticated (Subscriber+) Full Path Disclosure

medium

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 5.9.5.2. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information...

CVSS:
4.3
Affected:
up to 5.9.5.2
Fixed in:
5.9.5.3
Disclosed:
Jun 19, 2025

CVE-2025-52719 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.9.5.3

unknown

[en] Server-Side Request Forgery (SSRF) vulnerability in Metagauss ProfileGrid allows Server Side Request Forgery. This issue affects ProfileGrid : from n/a through 5.9.5.2.

Affected:
up to 5.9.5.3
Fixed in:
5.9.5.3
Disclosed:
Jun 17, 2025

CVE-2025-49877 on NVD →

ProfileGrid <= 5.9.5.2 - Authenticated (Subscriber+) Server-Side Request Forgery

medium

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.9.5.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating fro...

CVSS:
6.4
Affected:
up to 5.9.5.2
Fixed in:
5.9.5.3
Disclosed:
Jun 12, 2025

CVE-2025-49877 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.9.5.1

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid allows SQL Injection. This issue affects ProfileGrid : from n/a through 5.9.5.0.

Affected:
up to 5.9.5.1
Fixed in:
5.9.5.1
Disclosed:
May 23, 2025

CVE-2025-47478 on NVD →

ProfileGrid <= 5.9.5.1 - Missing Authorization

medium

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.9.5.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unaut...

CVSS:
4.3
Affected:
up to 5.9.5.1
Fixed in:
5.9.5.2
Disclosed:
May 16, 2025

CVE-2025-48079 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.9.5.2

unknown

[en] Missing Authorization vulnerability in Metagauss ProfileGrid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ProfileGrid : from n/a through 5.9.5.1.

Affected:
up to 5.9.5.2
Fixed in:
5.9.5.2
Disclosed:
May 16, 2025

CVE-2025-48079 on NVD →

ProfileGrid <= 5.9.5.0 - Authenticated (Subscriber+) SQL Injection

medium

The ProfileGrid plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.9.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and a...

CVSS:
6.5
Affected:
up to 5.9.5.0
Fixed in:
5.9.5.1
Disclosed:
May 12, 2025

CVE-2025-47478 on NVD →

ProfileGrid <= 5.9.4.8 - Authenticated (Subscriber+) SQL Injection

medium

The ProfileGrid plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.9.4.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and a...

CVSS:
6.5
Affected:
up to 5.9.4.8
Fixed in:
5.9.4.9
Disclosed:
Apr 17, 2025

CVE-2025-39586 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.9.4.9

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid allows SQL Injection. This issue affects ProfileGrid : from n/a through 5.9.4.8.

Affected:
up to 5.9.4.9
Fixed in:
5.9.4.9
Disclosed:
Apr 17, 2025

CVE-2025-39586 on NVD →

ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.5 - Authenticated (Subscriber+) PHP Object Injection

high

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.4.5 via deserialization of untrusted input in the get_user_meta_fields_html function. This makes it possible for authenticated attackers, with Subscriber-level acc...

CVSS:
8.8
Affected:
up to 5.9.4.5
Fixed in:
5.9.4.6
Disclosed:
Mar 21, 2025

CVE-2025-0724 on NVD →

ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.4 - Missing Authorinzation to Authenticated (Subscriber+) Join Group Requests Management

medium

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_decline_join_group_request and pm_approve_join_group_request functions in all versions up to, and including, 5.9.4.4. This makes it possible for aut...

CVSS:
4.3
Affected:
up to 5.9.4.4
Fixed in:
5.9.4.5
Disclosed:
Mar 21, 2025

CVE-2025-1408 on NVD →

ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.7 - Authenticated (Subscriber+) SQL Injection

medium

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind and time-based SQL Injections via the rid and search parameters in all versions up to, and including, 5.9.4.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing...

CVSS:
6.5
Affected:
up to 5.9.4.7
Fixed in:
5.9.4.8
Disclosed:
Mar 21, 2025

CVE-2025-0723 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.9.4.4

unknown

[en] Deserialization of Untrusted Data vulnerability in Metagauss ProfileGrid allows Object Injection. This issue affects ProfileGrid : from n/a through 5.9.4.3.

Affected:
up to 5.9.4.4
Fixed in:
5.9.4.4
Disclosed:
Mar 3, 2025

CVE-2025-26999 on NVD →

ProfileGrid <= 5.9.4.3 - Authenticated (Subscriber+) PHP Object Injection

high

The ProfileGrid plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.9.4.3 via deserialization of untrusted input. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerabl...

CVSS:
8.8
Affected:
up to 5.9.4.3
Fixed in:
5.9.4.4
Disclosed:
Feb 23, 2025

CVE-2025-26999 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.9.4.3

unknown

[en] The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.4.2 via the pm_messenger_show_messages function due to missing validation on a user controlled key. This makes it possible for authenticated attac...

Affected:
up to 5.9.4.3
Fixed in:
5.9.4.3
Disclosed:
Feb 18, 2025

CVE-2024-13740 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.9.4.3

unknown

[en] The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 5.9.4.2 via the pm_upload_image function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web r...

Affected:
up to 5.9.4.3
Fixed in:
5.9.4.3
Disclosed:
Feb 18, 2025

CVE-2024-13741 on NVD →

ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.2 - Insecure Direct Object Reference to Authenticated (Subscriber+) Private Messages Disclosure

medium

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.4.2 via the pm_messenger_show_messages function due to missing validation on a user controlled key. This makes it possible for authenticated attackers,...

CVSS:
4.3
Affected:
up to 5.9.4.2
Fixed in:
5.9.4.3
Disclosed:
Feb 17, 2025

CVE-2024-13740 on NVD →

ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.2 - Authenticated (Subscriber+) Limited Server-Side Request Forgery

medium

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 5.9.4.2 via the pm_upload_image function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web reques...

CVSS:
5.4
Affected:
up to 5.9.4.2
Fixed in:
5.9.4.3
Disclosed:
Feb 17, 2025

CVE-2024-13741 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.9.3.7

unknown

[en] The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_remove_file_attachment() function in all versions up to, and including, 5.9.3.6. This makes it possible for authenticated attackers, with subsc...

Affected:
up to 5.9.3.7
Fixed in:
5.9.3.7
Disclosed:
Nov 20, 2024

CVE-2024-10900 on NVD →

ProfileGrid – User Profiles, Groups and Communities <= 5.9.3.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Meta Deletion

medium

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_remove_file_attachment() function in all versions up to, and including, 5.9.3.6. This makes it possible for authenticated attackers, with subscriber...

CVSS:
6.5
Affected:
up to 5.9.3.6
Fixed in:
5.9.3.7
Disclosed:
Nov 19, 2024

CVE-2024-10900 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.8.8

unknown

[en] Missing Authorization vulnerability in ProfileGrid User Profiles ProfileGrid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfileGrid: from n/a through 5.8.7.

Affected:
up to 5.8.8
Fixed in:
5.8.8
Disclosed:
Nov 1, 2024

CVE-2024-37453 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.9.3.1

unknown

[en] Missing Authorization vulnerability in ProfileGrid User Profiles ProfileGrid.This issue affects ProfileGrid: from n/a through 5.9.3.

Affected:
up to 5.9.3.1
Fixed in:
5.9.3.1
Disclosed:
Oct 21, 2024

CVE-2024-49273 on NVD →

ProfileGrid <= 5.9.3 - Cross-Site Request Forgery

medium

The ProfileGrid plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.9.3. This is due to missing or incorrect nonce validation on the pg_create_group_page() function. This makes it possible for unauthenticated attackers to create group pages via a forged request granted...

CVSS:
4.3
Affected:
up to 5.9.3
Fixed in:
5.9.3.1
Disclosed:
Oct 14, 2024

CVE-2024-49273 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.9.3.3

unknown

[en] The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.9.3.2 due to incorrect use of the wp_kses_allowed_html function, which allows the 'onclick' attribute for certain HTML elements without sufficient restri...

Affected:
up to 5.9.3.3
Fixed in:
5.9.3.3
Disclosed:
Sep 26, 2024

CVE-2024-8861 on NVD →

ProfileGrid – User Profiles, Groups and Communities <= 5.9.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.9.3.2 due to incorrect use of the wp_kses_allowed_html function, which allows the 'onclick' attribute for certain HTML elements without sufficient restriction...

CVSS:
6.4
Affected:
up to 5.9.3.2
Fixed in:
5.9.3.3
Disclosed:
Sep 25, 2024

CVE-2024-8861 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.9.0

unknown

[en] The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.8.9. This is due to a lack of validation on user-supplied data in the 'pm_upload_image' AJAX action. This makes it possible for authenticated attackers, with Su...

Affected:
up to 5.9.0
Fixed in:
5.9.0
Disclosed:
Jul 10, 2024

CVE-2024-6411 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.9.0

unknown

[en] The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.8.9 via the 'pm_upload_image' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with...

Affected:
up to 5.9.0
Fixed in:
5.9.0
Disclosed:
Jul 10, 2024

CVE-2024-6410 on NVD →

ProfileGrid <= 5.8.9 - Authenticated (Subscriber+) Insecure Direct Object Reference

medium

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.8.9 via the 'pm_upload_image' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subsc...

CVSS:
4.3
Affected:
up to 5.8.9
Fixed in:
5.9.0
Disclosed:
Jul 9, 2024

CVE-2024-6410 on NVD →

ProfileGrid – User Profiles, Groups and Communities <= 5.8.9 - Authenticated (Subscriber+) Authorization Bypass to Privilege Escalation

high

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.8.9. This is due to a lack of validation on user-supplied data in the 'pm_upload_image' AJAX action. This makes it possible for authenticated attackers, with Subscri...

CVSS:
8.8
Affected:
up to 5.8.9
Fixed in:
5.9.0
Disclosed:
Jul 9, 2024

CVE-2024-6411 on NVD →

ProfileGrid <= 5.8.7 - Missing Authorization

medium

The ProfileGrid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the pm_create_message function in versions up to, and including, 5.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to send messages even when they haven't been...

CVSS:
5.4
Affected:
up to 5.8.7
Fixed in:
5.8.8
Disclosed:
Jul 1, 2024

CVE-2024-37453 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.6.7

unknown

[en] Missing Authorization vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid: from n/a through 5.6.6.

Affected:
up to 5.6.7
Fixed in:
5.6.7
Disclosed:
Jun 12, 2024

CVE-2023-52117 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.8.7

unknown

[en] The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_dismissible_notice and pm_wizard_update_group_icon functions in all versions up to, and including, 5.8.6. This makes it possible for authentica...

Affected:
up to 5.8.7
Fixed in:
5.8.7
Disclosed:
Jun 5, 2024

CVE-2024-5453 on NVD →

ProfileGrid <= 5.8.6 - Missing Authorization

medium

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_dismissible_notice and pm_wizard_update_group_icon functions in all versions up to, and including, 5.8.6. This makes it possible for authenticated a...

CVSS:
4.3
Affected:
up to 5.8.6
Fixed in:
5.8.7
Disclosed:
Jun 4, 2024

CVE-2024-5453 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.8.3

unknown

[en] Improper Restriction of Excessive Authentication Attempts vulnerability in Metagauss ProfileGrid allows Removing Important Client Functionality.This issue affects ProfileGrid : from n/a through 5.8.2.

Affected:
up to 5.8.3
Fixed in:
5.8.3
Disclosed:
May 17, 2024

CVE-2024-32774 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.8.4

unknown

[en] The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the pm_upload_cover_image function in all versions up to, and including, 5.8.3. This makes it possible for authenticated attackers, with subs...

Affected:
up to 5.8.4
Fixed in:
5.8.4
Disclosed:
May 2, 2024

CVE-2024-3606 on NVD →

ProfileGrid <= 5.7.1 - Authenticated (Contributor+) SQL Injection

medium

The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 5.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authen...

CVSS:
6.4
Affected:
up to 5.7.1
Fixed in:
5.7.2
Disclosed:
Apr 26, 2024

CVE-2024-30241 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.8.0

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9.

Affected:
up to 5.8.0
Fixed in:
5.8.0
Disclosed:
Apr 24, 2024

CVE-2024-32808 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.8.0

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9.

Affected:
up to 5.8.0
Fixed in:
5.8.0
Disclosed:
Apr 24, 2024

CVE-2024-32772 on NVD →

ProfileGrid <= 5.8.2 - Bypass Group Members Limit

medium

The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to group limit bypass in all versions up to, and including, 5.8.2. This is due to the plugin not properly verifying the limits of a group before adding a member. This makes it possible for authenticated attackers, wi...

CVSS:
5.3
Affected:
up to 5.8.2
Fixed in:
5.8.3
Disclosed:
Apr 22, 2024

CVE-2024-32774 on NVD →

ProfileGrid – User Profiles, Memberships, Groups and Communities <= 5.7.9 - Insecure Direct Object Reference

medium

The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.7.9 due to missing validation on a user controlled key in the pg_show_msg_panel() function. This makes it possible for authenticated attacke...

CVSS:
4.3
Affected:
up to 5.7.9
Fixed in:
5.8.0
Disclosed:
Apr 22, 2024

CVE-2024-32808 on NVD →

ProfileGrid – User Profiles, Memberships, Groups and Communities <= 5.7.9 - Insecure Direct Object Reference

medium

The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.7.9 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and...

CVSS:
4.3
Affected:
up to 5.7.9
Fixed in:
5.8.0
Disclosed:
Apr 22, 2024

CVE-2024-32772 on NVD →

ProfileGrid – User Profiles, Memberships, Groups and Communities <= 5.8.3 - Missing Authorization

medium

The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the pm_upload_cover_image function in all versions up to, and including, 5.8.3. This makes it possible for authenticated attackers, with subscribe...

CVSS:
4.3
Affected:
up to 5.8.3
Fixed in:
5.8.4
Disclosed:
Apr 16, 2024

CVE-2024-3606 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.7.9

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8.

Affected:
up to 5.7.9
Fixed in:
5.7.9
Disclosed:
Apr 12, 2024

CVE-2024-31362 on NVD →

ProfileGrid <= 5.7.8 - Cross-Site Request Forgery

medium

The ProfileGrid plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.7.8. This is due to missing or incorrect nonce validation in the admin/partials/add-group.php file. This makes it possible for unauthenticated attackers to delete groups via a forged request granted the...

CVSS:
4.3
Affected:
up to 5.7.8
Fixed in:
5.7.9
Disclosed:
Apr 8, 2024

CVE-2024-31362 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.7.7

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.6.

Affected:
up to 5.7.7
Fixed in:
5.7.7
Disclosed:
Apr 7, 2024

CVE-2024-31291 on NVD →

ProfileGrid <= 5.7.6 - Authenticated (Subscriber+) Insecure Direct Object Reference

medium

The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.7.6 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and...

CVSS:
4.3
Affected:
up to 5.7.6
Fixed in:
5.7.7
Disclosed:
Apr 5, 2024

CVE-2024-31291 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.7.3

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.2.

Affected:
up to 5.7.3
Fixed in:
5.7.3
Disclosed:
Mar 29, 2024

CVE-2024-30513 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.7.9

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8.

Affected:
up to 5.7.9
Fixed in:
5.7.9
Disclosed:
Mar 29, 2024

CVE-2024-30490 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.7.9

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8.

Affected:
up to 5.7.9
Fixed in:
5.7.9
Disclosed:
Mar 29, 2024

CVE-2024-30491 on NVD →

ProfileGrid <= 5.7.8 - Unauthenticated SQL Injection

critical

The ProfileGrid plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.7.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries in...

CVSS:
10
Affected:
up to 5.7.8
Fixed in:
5.7.9
Disclosed:
Mar 28, 2024

CVE-2024-30490 on NVD →

ProfileGrid <= 5.7.8 - Authenticated (Subscriber+) SQL Injection

critical

The ProfileGrid plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.7.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and abo...

CVSS:
9.9
Affected:
up to 5.7.8
Fixed in:
5.7.9
Disclosed:
Mar 28, 2024

CVE-2024-30491 on NVD →

ProfileGrid <= 5.7.2 - Authenticated (Subscriber+) Insecure Direct Object Reference

medium

The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.7.2 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and...

CVSS:
4.3
Affected:
up to 5.7.2
Fixed in:
5.7.3
Disclosed:
Mar 28, 2024

CVE-2024-30513 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.7.2

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.1.

Affected:
up to 5.7.2
Fixed in:
5.7.2
Disclosed:
Mar 28, 2024

CVE-2024-30241 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.0.4

unknown

[en] Missing Authorization vulnerability in Profilegrid ProfileGrid – User Profiles, Memberships, Groups and Communities.This issue affects ProfileGrid – User Profiles, Memberships, Groups and Communities: from n/a through 5.0.3.

Affected:
up to 5.0.4
Fixed in:
5.0.4
Disclosed:
Jan 8, 2024

CVE-2022-36352 on NVD →

ProfileGrid <= 5.6.6 - Missing Authorization

medium

The ProfileGrid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.6.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions.

CVSS:
4.3
Affected:
up to 5.6.6
Fixed in:
5.6.7
Disclosed:
Dec 28, 2023

CVE-2023-52117 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.7.2

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in profilegrid ProfileGrid – User Profiles, Memberships, Groups and Communities.This issue affects ProfileGrid – User Profiles, Memberships, Groups and Communities: from n/a through 5.6.6.

Affected:
up to 5.7.2
Fixed in:
5.7.2
Disclosed:
Nov 18, 2023

CVE-2023-47644 on NVD →

ProfileGrid <= 5.7.1 - Cross-Site Request Forgery

medium

The ProfileGrid plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.7.1. This is due to missing nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a...

CVSS:
4.3
Affected:
up to 5.7.1
Fixed in:
5.7.2
Disclosed:
Nov 7, 2023

CVE-2023-47644 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.5.1

unknown

[en] The ProfileGrid plugin for WordPress is vulnerable to unauthorized decryption of private information in versions up to, and including, 5.5.0. This is due to the passphrase and iv being hardcoded in the 'pm_encrypt_decrypt_pass' function and used across all sites running the plugin. This makes it possible for authe...

Affected:
up to 5.5.1
Fixed in:
5.5.1
Disclosed:
Aug 31, 2023

CVE-2023-3404 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.5.2

unknown

[en] The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pm_upload_csv' function in versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with subscriber-level permissions or above to import new users and u...

Affected:
up to 5.5.2
Fixed in:
5.5.2
Disclosed:
Jul 18, 2023

CVE-2023-3403 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.5.3

unknown

[en] The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'edit_group' handler in versions up to, and including, 5.5.2. This makes it possible for authenticated attackers, with group ownership, to update group options, including the 'associate_...

Affected:
up to 5.5.3
Fixed in:
5.5.3
Disclosed:
Jul 18, 2023

CVE-2023-3714 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.5.2

unknown

[en] The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'profile_magic_check_smtp_connection' function in versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with subscriber-level permissions or above to...

Affected:
up to 5.5.2
Fixed in:
5.5.2
Disclosed:
Jul 18, 2023

CVE-2023-3713 on NVD →

ProfileGrid <= 5.5.1 - Authenticated (Subscriber+) Arbitrary Option Update

high

The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'profile_magic_check_smtp_connection' function in versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with subscriber-level permissions or above to updat...

CVSS:
8.8
Affected:
up to 5.5.1
Fixed in:
5.5.2
Disclosed:
Jul 17, 2023

CVE-2023-3713 on NVD →

ProfileGrid <= 5.5.2 - Missing Authorization to Arbitrary Group Option Modification and Privilege Escalation

high

The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'edit_group' handler in versions up to, and including, 5.5.2. This makes it possible for authenticated attackers, with group ownership, to update group options, including the 'associate_role'...

CVSS:
7.5
Affected:
up to 5.5.2
Fixed in:
5.5.3
Disclosed:
Jul 17, 2023

CVE-2023-3714 on NVD →

ProfileGrid <= 5.5.1 - Missing Authorization to User Import

medium

The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pm_upload_csv' function in versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with subscriber-level permissions or above to import new users and update...

CVSS:
5.4
Affected:
up to 5.5.1
Fixed in:
5.5.2
Disclosed:
Jul 17, 2023

CVE-2023-3403 on NVD →

ProfileGrid <= 5.5.0 - Hardcoded Encryption Key

medium

The ProfileGrid plugin for WordPress is vulnerable to unauthorized decryption of private information in versions up to, and including, 5.5.0. This is due to the passphrase and iv being hardcoded in the 'pm_encrypt_decrypt_pass' function and used across all sites running the plugin. This makes it possible for authentica...

CVSS:
4.9
Affected:
up to 5.5.0
Fixed in:
5.5.1
Disclosed:
Jul 17, 2023

CVE-2023-3404 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.3.1

unknown

[en] The ProfileGrid WordPress plugin before 5.3.1 provides an AJAX endpoint for resetting a user password but does not implement proper authorization. This allows a user with low privileges, such as subscriber, to change the password of any account, including Administrator ones.

Affected:
up to 5.3.1
Fixed in:
5.3.1
Disclosed:
Mar 20, 2023

CVE-2023-0940 on NVD →

ProfileGrid <= 5.3.0 - Missing Authorization to Arbitrary Password Reset

high

The ProfileGrid plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the pm_reset_user_password function in versions up to, and including, 5.3.0. This makes it possible for authenticated attackers, with subscriber-level access or higher, to change the passwords of any user.

CVSS:
8.8
Affected:
up to 5.3.0
Fixed in:
5.3.1
Disclosed:
Feb 27, 2023

CVE-2023-0940 on NVD →

ProfileGrid <= 5.1.7 - Authenticated (Subscriber+) CSV Injection

medium

The ProfileGrid plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 5.1.6, via the 'pm_get_csv_single_user_row' function. This allows subscriber-level attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and open...

CVSS:
6.3
Affected:
up to 5.1.7
Fixed in:
5.1.8
Disclosed:
Nov 17, 2022

CVE-2022-41791 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.1.8

unknown

[en] Auth. (subscriber+) CSV Injection vulnerability in ProfileGrid plugin <= 5.1.6 on WordPress.

Affected:
up to 5.1.8
Fixed in:
5.1.8
Disclosed:
Nov 17, 2022

CVE-2022-41791 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.1.1

unknown

[en] The ProfileGrid WordPress plugin before 5.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

Affected:
up to 5.1.1
Fixed in:
5.1.1
Disclosed:
Nov 14, 2022

CVE-2022-3578 on NVD →

ProfileGrid – User Profiles, Memberships, Groups and Communities <= 5.0.3 - Missing Authorization to Information Exposure

medium

The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when accessing messages in versions up to, and including, 5.0.3. This makes it possible for authenticated attackers, with subscriber-level permissions and abo...

CVSS:
5.4
Affected:
up to 5.0.3
Fixed in:
5.0.4
Disclosed:
Oct 27, 2022

CVE-2022-36352 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.0.4

unknown

The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when accessing messages in versions up to, and including, 5.0.3. This makes it possible for authenticated attackers, with subscriber-level permissions and abo...

Affected:
up to 5.0.4
Fixed in:
5.0.4
Disclosed:
Oct 27, 2022

ProfileGrid – User Profiles, Memberships, Groups and Communities <= 5.1.0 - Reflected Cross-Site Scripting

medium

The ProfileGrid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in versions up to, and including, 5.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if th...

CVSS:
6.1
Affected:
up to 5.1.0
Fixed in:
5.1.1
Disclosed:
Oct 19, 2022

CVE-2022-3578 on NVD →

ProfileGrid – User Profiles, Memberships, Groups and Communities <= 4.7.4 - Stored Cross-Site Scripting via Profile

medium

The ProfileGrid – User Profiles, Memberships, Groups and Communities WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the pm_user_avatar and pm_cover_image parameters found in the ~/admin/class-profile-magic-admin.php file which allows attackers with authenticated user acce...

CVSS:
6.4
Affected:
up to 4.7.4
Fixed in:
4.7.7
Disclosed:
Jan 18, 2022

CVE-2022-0233 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 4.7.7

unknown

[en] The ProfileGrid – User Profiles, Memberships, Groups and Communities WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the pm_user_avatar and pm_cover_image parameters found in the ~/admin/class-profile-magic-admin.php file which allows attackers with authenticated user...

Affected:
up to 4.7.7
Fixed in:
4.7.7
Disclosed:
Jan 18, 2022

CVE-2022-0233 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 2.8.6

unknown

[en] The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an wp-admin/admin-ajax.php request with the action=pm_template_preview&html=<?php substring followed by PHP code.

Affected:
up to 2.8.6
Fixed in:
2.8.6
Disclosed:
Sep 3, 2019

CVE-2019-15873 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 2.8.6

unknown

Authenticated Code Execution vulnerability found in WordPress ProfileGrid– User Profiles, Groups and Communities plugin (versions <= 2.8.5).

Affected:
up to 2.8.6
Fixed in:
2.8.6
Disclosed:
Jun 5, 2018

ProfileGrid – User Profiles, Memberships, Groups and Communities < 2.8.6 - Remote Code Execution

high

The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an wp-admin/admin-ajax.php request with the action=pm_template_preview&html=<?php substring followed by PHP code.

CVSS:
8.8
Affected:
up to 2.8.6
Fixed in:
2.8.6
Disclosed:
May 18, 2018

CVE-2019-15873 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 2.6.7

unknown

A reflected cross-site scripting vulnerability was found in ProfileGrid plugin in 2.6.6 version. The vulnerability exists in the file /admin/partials/user-manager.php. There some of $_GET parameters are not escaped. For example: if(isset($_GET[‘search’])) echo $_GET[‘search’]; …

Affected:
up to 2.6.7
Fixed in:
2.6.7
Disclosed:
Nov 27, 2017

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.0.4

unknown

The plugin does not have any authorisation and CSRF checks when accessing and editing messages, which could allow any logged in users, such as subscriber to access and edit arbitrary messages

Affected:
up to 5.0.4
Fixed in:
5.0.4

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.9.4.8

unknown
Affected:
up to 5.9.4.8
Fixed in:
5.9.4.8

CVE-2025-0723 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.9.4.5

unknown
Affected:
up to 5.9.4.5
Fixed in:
5.9.4.5

CVE-2025-1408 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.9.4.6

unknown
Affected:
up to 5.9.4.6
Fixed in:
5.9.4.6

CVE-2025-0724 on NVD →

ProfileGrid – User Profiles, Groups and Communities [profilegrid-user-profiles-groups-and-communities] < 5.9.5.5

unknown
Affected:
up to 5.9.5.5
Fixed in:
5.9.5.5

CVE-2025-6977 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database