Skip to main content

Vendor/product archive

metagauss / profilegrid CVEs

Beta · best-effort

35 CVEs tagged to metagauss / profilegrid1 Critical, 8 High, 26 Medium, 0 Low, 0 Unrated.

CVE-2025-6977

Published Jul 16, 2025

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘pm_get_messenger_notification’ function in al…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1408

Published Mar 22, 2025

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_decline…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2025-0724

Published Mar 22, 2025

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.4.5 via deserializatio…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-0723

Published Mar 22, 2025

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind and time-based SQL Injections via the rid and search parameters in all versions…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2024-13740

Published Feb 18, 2025

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.4.2 via th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13741

Published Feb 18, 2025

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 5.9.4.2 via…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10900

Published Nov 20, 2024

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_remove_…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37453

Published Nov 1, 2024

Missing Authorization vulnerability in ProfileGrid User Profiles ProfileGrid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfileGrid…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-49273

Published Oct 21, 2024

Missing Authorization vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities.This issue affects ProfileGrid : from n/a through <= 5.9.3.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8861

Published Sep 26, 2024

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.9.3.2 due to inco…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6411

Published Jul 10, 2024

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.8.9. This is due to a la…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-6410

Published Jul 10, 2024

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.8.9 via the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-52117

Published Jun 12, 2024

Missing Authorization vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid: from n/a through 5.6.6.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-5453

Published Jun 5, 2024

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_dismiss…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32774

Published May 17, 2024

Improper Restriction of Excessive Authentication Attempts vulnerability in Metagauss ProfileGrid allows Removing Important Client Functionality.This issue affects ProfileGrid : fr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3606

Published May 2, 2024

The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the p…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32808

Published Apr 24, 2024

Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32772

Published Apr 24, 2024

Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31362

Published Apr 12, 2024

Cross-Site Request Forgery (CSRF) vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31291

Published Apr 7, 2024

Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.6.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30513

Published Mar 29, 2024

Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.2.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30491

Published Mar 29, 2024

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8.

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-30490

Published Mar 29, 2024

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-30241

Published Mar 28, 2024

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.1.

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36352

Published Jan 8, 2024

Missing Authorization vulnerability in Profilegrid ProfileGrid – User Profiles, Memberships, Groups and Communities.This issue affects ProfileGrid – User Profiles, Memberships, Gr…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 35 CVEsPage 1 of 2