Skip to main content

Vendor archive

metagauss CVEs

Beta · best-effort

104 CVEs tagged to vendor metagauss5 Critical, 31 High, 68 Medium, 0 Low, 0 Unrated.

CVE-2017-20208

Published Oct 18, 2025

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.7.…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-6977

Published Jul 16, 2025

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘pm_get_messenger_notification’ function in al…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-6586

Published Jul 4, 2025

The Download Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the dpwap_plugin_locInstall function in all versions up to,…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-9390

Published May 15, 2025

The RegistrationMagic WordPress plugin before 6.0.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cr…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4665

Published May 15, 2025

The EventPrime WordPress plugin before 3.5.0 does not properly validate permissions when updating bookings, allowing users to change/cancel bookings for other users. Additionally,…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1408

Published Mar 22, 2025

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_decline…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2025-0724

Published Mar 22, 2025

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.4.5 via deserializatio…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-0723

Published Mar 22, 2025

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind and time-based SQL Injections via the rid and search parameters in all versions…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2024-13526

Published Mar 7, 2025

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks on the export_submittio…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13740

Published Feb 18, 2025

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.4.2 via th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13741

Published Feb 18, 2025

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 5.9.4.2 via…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24686

Published Jan 31, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-12024

Published Dec 17, 2024

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the em_ticket_category_data and em_ticket_individual_d…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-49831

Published Dec 9, 2024

Missing Authorization vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Exploiting Incorrectly Configured Access Control…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-10900

Published Nov 20, 2024

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_remove_…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10508

Published Nov 9, 2024

The RegistrationMagic – User Registration Plugin with Custom Registration Forms plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-43223

Published Nov 1, 2024

Missing Authorization vulnerability in EventPrime Events EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37453

Published Nov 1, 2024

Missing Authorization vulnerability in ProfileGrid User Profiles ProfileGrid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfileGrid…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9865

Published Oct 24, 2024

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ep_booking_attendee_fields’ fields in all version…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9864

Published Oct 24, 2024

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ticket names in all versions up to, and including, 4.0…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9829

Published Oct 23, 2024

The Download Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks on the 'dpwap_handle_download_user' and 'dpwap_handle_down…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-49273

Published Oct 21, 2024

Missing Authorization vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities.This issue affects ProfileGrid : from n/a through <= 5.9.3.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8861

Published Sep 26, 2024

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.9.3.2 due to inco…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8369

Published Sep 10, 2024

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access to Private or Password-protected events due to missing authorizati…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-43317

Published Aug 19, 2024

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Metagauss User Registration Team RegistrationMagic allows Cross-Site S…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 104 CVEsPage 1 of 5