Metagauss

Profilegrid

56 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.32%
  • Veröffentlicht 13.07.2026 08:41:24
  • Zuletzt bearbeitet 13.07.2026 16:57:56

Authentication Bypass Using an Alternate Path or Channel vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Password Recovery Exploitation.This issue affects ProfileGrid : from n/a through <= 5.9.9.6.

  • EPSS 0.14%
  • Veröffentlicht 02.07.2026 11:16:02
  • Zuletzt bearbeitet 02.07.2026 20:17:05

Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions.

  • EPSS 0.31%
  • Veröffentlicht 30.06.2026 05:34:05
  • Zuletzt bearbeitet 30.06.2026 14:16:25

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.9.9.5. This is due to the plugin not validating a `user_login` on registra...

  • EPSS 0.2%
  • Veröffentlicht 23.06.2026 12:32:56
  • Zuletzt bearbeitet 29.06.2026 20:17:38

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pm_author_message' parameter in the pm_send_message_to_author function in all versions up to, and including, 5.9.9.2 du...

  • EPSS 0.22%
  • Veröffentlicht 13.05.2026 13:27:54
  • Zuletzt bearbeitet 13.05.2026 14:43:46

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the pm_invite_user function in all versions up to, and including, 5.9.8.4. This makes it possible f...

  • EPSS 0.23%
  • Veröffentlicht 13.05.2026 13:27:54
  • Zuletzt bearbeitet 13.05.2026 14:43:46

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.9.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an...

  • EPSS 0.27%
  • Veröffentlicht 13.05.2026 13:27:53
  • Zuletzt bearbeitet 13.05.2026 14:43:46

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind SQL Injection via the 'rid' parameter in all versions up to, and including, 5.9.8.4 due to insufficient escaping on the user supplied parameter and la...

  • EPSS 0.16%
  • Veröffentlicht 25.03.2026 16:14:49
  • Zuletzt bearbeitet 24.04.2026 16:35:20

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Stored XSS.This issue affects ProfileGrid : from n/a through <= 5.9.8...

  • EPSS 0.13%
  • Veröffentlicht 07.03.2026 01:21:22
  • Zuletzt bearbeitet 22.04.2026 21:27:27

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.9.8.2. This is due to missing nonce validation on the membership request management page ...

  • EPSS 0.22%
  • Veröffentlicht 07.03.2026 01:21:21
  • Zuletzt bearbeitet 22.04.2026 21:27:27

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized message deletion due to a missing capability check on the pg_delete_msg() function in all versions up to, and including, 5.9.8.1. This is due t...