Extension WordPress

Vulnérabilités ProfileGrid – User Profiles, Groups and Communities

Cette page rassemble les failles publiées pour ProfileGrid – User Profiles, Groups and Communities, leurs plages de versions affectées et les correctifs signalés dans la base locale.

56Vulnérabilités
4Critiques
55Avec correctif
10,0CVSS maximal

Historique de sécurité

CVE et vulnérabilités de ProfileGrid – User Profiles, Groups and Communities

56 fiches

CVE-2026-57697 Critique · 9,8
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid – User Profiles, Groups and Communities <= 5.9.9.6 – Unauthenticated Privilege Escalation via Password Reset

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.9.9.6. This is due to the plugin not properly validating a user's…

Versions affectées

*-5.9.9.6

Correctif

5.9.9.7

Publication

08/07/2026

CVE-2026-57759 Moyenne · 4,3
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid – User Profiles, Groups and Communities <= 5.9.9.8 – Cross-Site Request Forgery

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.9.9.8. This is due to missing or incorrect nonce validation on a function. This makes…

Versions affectées

*-5.9.9.8

Correctif

Non indiqué

Publication

02/07/2026

CVE-2026-12073 Critique · 9,8
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid – User Profiles, Groups and Communities <= 5.9.9.5 – Unauthenticated Privilege Escalation via Email Overwrite

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.9.9.5. This is due to the plugin not validating a `user_login` on…

Versions affectées

*-5.9.9.5

Correctif

5.9.9.6

Publication

29/06/2026

CVE-2026-4610 Moyenne · 6,4
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid <= 5.9.9.2 – Authenticated (Subscriber+) Stored Cross-Site Scripting via Message Content

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pm_author_message' parameter in the pm_send_message_to_author function in all versions up to, and including, 5.9.9.2 due to insufficient input sanitization…

Versions affectées

*-5.9.9.2

Correctif

5.9.9.3

Publication

22/06/2026

CVE-2026-4609 Élevée · 7,1
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid <= 5.9.8.4 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Group Joining

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the pm_invite_user function in all versions up to, and including, 5.9.8.4. This makes it possible…

Versions affectées

*-5.9.8.4

Correctif

5.9.8.5

Publication

12/05/2026

CVE-2026-4607 Moyenne · 4,3
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid <= 5.9.8.4 – Missing Authorization to Authenticated (Subscriber+) Group Settings Modification

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.9.8.4. This is due to the plugin not properly verifying that a user is authorized…

Versions affectées

*-5.9.8.4

Correctif

5.9.8.5

Publication

12/05/2026

CVE-2026-4608 Moyenne · 6,5
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid <= 5.9.8.4 – Authenticated (Subscriber+) SQL Injection via 'rid' Parameter

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind SQL Injection via the 'rid' parameter in all versions up to, and including, 5.9.8.4 due to insufficient escaping on the user supplied parameter…

Versions affectées

*-5.9.8.4

Correctif

5.9.8.5

Publication

12/05/2026

CVE-2026-25417 Moyenne · 6,4
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid – User Profiles, Groups and Communities <= 5.9.8.1 – Authenticated (Subscriber+) Stored Cross-Site Scripting

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.9.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

Versions affectées

*-5.9.8.1

Correctif

5.9.8.2

Publication

23/03/2026

CVE-2026-2488 Moyenne · 4,3
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid <= 5.9.8.1 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Message Deletion

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized message deletion due to a missing capability check on the pg_delete_msg() function in all versions up to, and including, 5.9.8.1. This is due…

Versions affectées

*-5.9.8.1

Correctif

5.9.8.2

Publication

06/03/2026

CVE-2026-2494 Moyenne · 4,3
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid <= 5.9.8.2 – Cross-Site Request Forgery to Group Membership Request Approval/Denial

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.9.8.2. This is due to missing nonce validation on the membership request management page…

Versions affectées

*-5.9.8.2

Correctif

5.9.8.3

Publication

06/03/2026

CVE-2026-1271 Moyenne · 5,3
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid <= 5.9.7.2 – Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Profile and Cover Image Modification

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.7.2 via the 'pm_upload_image' and 'pm_upload_cover_image' AJAX actions. This is due to the…

Versions affectées

*-5.9.7.2

Correctif

5.9.7.3

Publication

04/02/2026

CVE-2025-13416 Moyenne · 4,3
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid – User Profiles, Groups and Communities <= 5.9.7.2 – Missing Authorization to Authenticated (Subscriber+) Arbitrary User Suspension

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized user suspension due to a missing capability check on the pm_deactivate_user_from_group() function in all versions up to, and including, 5.9.7.2. This makes it…

Versions affectées

*-5.9.7.2

Correctif

5.9.7.3

Publication

04/02/2026

CVE-2025-4957 Moyenne · 6,1
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid – User Profiles, Groups and Communities <= 5.9.5.7 – Reflected Cross-Site Scripting

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 5.9.5.7 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-5.9.5.7

Correctif

5.9.5.8

Publication

01/09/2025

CVE-2025-6977 Moyenne · 6,1
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid – User Profiles, Groups and Communities <= 5.9.5.4 – Reflected Cross-Site Scripting via 'pm_get_messenger_notification' function

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘pm_get_messenger_notification’ function in all versions up to, and including, 5.9.5.4 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-5.9.5.4

Correctif

5.9.5.5

Publication

15/07/2025

CVE-2025-52719 Moyenne · 4,3
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid <= 5.9.5.2 – Authenticated (Subscriber+) Full Path Disclosure

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 5.9.5.2. This makes it possible for unauthenticated attackers to retrieve the full path of…

Versions affectées

*-5.9.5.2

Correctif

5.9.5.3

Publication

19/06/2025

CVE-2025-49877 Moyenne · 6,4
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid <= 5.9.5.2 – Authenticated (Subscriber+) Server-Side Request Forgery

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.9.5.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…

Versions affectées

*-5.9.5.2

Correctif

5.9.5.3

Publication

12/06/2025

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités