Extension WordPress
Vulnérabilités ProfileGrid – User Profiles, Groups and Communities
Cette page rassemble les failles publiées pour ProfileGrid – User Profiles, Groups and Communities, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de ProfileGrid – User Profiles, Groups and Communities
56 fiches
ProfileGrid – User Profiles, Groups and Communities <= 5.9.9.6 – Unauthenticated Privilege Escalation via Password Reset
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.9.9.6. This is due to the plugin not properly validating a user's…
*-5.9.9.6
5.9.9.7
08/07/2026
ProfileGrid – User Profiles, Groups and Communities <= 5.9.9.8 – Cross-Site Request Forgery
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.9.9.8. This is due to missing or incorrect nonce validation on a function. This makes…
*-5.9.9.8
Non indiqué
02/07/2026
ProfileGrid – User Profiles, Groups and Communities <= 5.9.9.5 – Unauthenticated Privilege Escalation via Email Overwrite
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.9.9.5. This is due to the plugin not validating a `user_login` on…
*-5.9.9.5
5.9.9.6
29/06/2026
ProfileGrid <= 5.9.9.2 – Authenticated (Subscriber+) Stored Cross-Site Scripting via Message Content
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pm_author_message' parameter in the pm_send_message_to_author function in all versions up to, and including, 5.9.9.2 due to insufficient input sanitization…
*-5.9.9.2
5.9.9.3
22/06/2026
ProfileGrid <= 5.9.8.4 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Group Joining
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the pm_invite_user function in all versions up to, and including, 5.9.8.4. This makes it possible…
*-5.9.8.4
5.9.8.5
12/05/2026
ProfileGrid <= 5.9.8.4 – Missing Authorization to Authenticated (Subscriber+) Group Settings Modification
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.9.8.4. This is due to the plugin not properly verifying that a user is authorized…
*-5.9.8.4
5.9.8.5
12/05/2026
ProfileGrid <= 5.9.8.4 – Authenticated (Subscriber+) SQL Injection via 'rid' Parameter
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind SQL Injection via the 'rid' parameter in all versions up to, and including, 5.9.8.4 due to insufficient escaping on the user supplied parameter…
*-5.9.8.4
5.9.8.5
12/05/2026
ProfileGrid – User Profiles, Groups and Communities <= 5.9.8.1 – Authenticated (Subscriber+) Stored Cross-Site Scripting
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.9.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-5.9.8.1
5.9.8.2
23/03/2026
ProfileGrid <= 5.9.8.1 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Message Deletion
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized message deletion due to a missing capability check on the pg_delete_msg() function in all versions up to, and including, 5.9.8.1. This is due…
*-5.9.8.1
5.9.8.2
06/03/2026
ProfileGrid <= 5.9.8.2 – Cross-Site Request Forgery to Group Membership Request Approval/Denial
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.9.8.2. This is due to missing nonce validation on the membership request management page…
*-5.9.8.2
5.9.8.3
06/03/2026
ProfileGrid <= 5.9.7.2 – Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Profile and Cover Image Modification
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.7.2 via the 'pm_upload_image' and 'pm_upload_cover_image' AJAX actions. This is due to the…
*-5.9.7.2
5.9.7.3
04/02/2026
ProfileGrid – User Profiles, Groups and Communities <= 5.9.7.2 – Missing Authorization to Authenticated (Subscriber+) Arbitrary User Suspension
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized user suspension due to a missing capability check on the pm_deactivate_user_from_group() function in all versions up to, and including, 5.9.7.2. This makes it…
*-5.9.7.2
5.9.7.3
04/02/2026
ProfileGrid – User Profiles, Groups and Communities <= 5.9.5.7 – Reflected Cross-Site Scripting
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 5.9.5.7 due to insufficient input sanitization and output escaping. This makes it possible for…
*-5.9.5.7
5.9.5.8
01/09/2025
ProfileGrid <= 5.9.5.3 – Authenticated (Subscriber+) SQL Injection
The ProfileGrid plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.9.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
*-5.9.5.3
5.9.5.4
24/07/2025
ProfileGrid – User Profiles, Groups and Communities <= 5.9.5.4 – Reflected Cross-Site Scripting via 'pm_get_messenger_notification' function
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘pm_get_messenger_notification’ function in all versions up to, and including, 5.9.5.4 due to insufficient input sanitization and output escaping. This…
*-5.9.5.4
5.9.5.5
15/07/2025
ProfileGrid <= 5.9.5.2 – Authenticated (Subscriber+) SQL Injection
The ProfileGrid plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.9.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
*-5.9.5.2
5.9.5.3
10/07/2025
ProfileGrid <= 5.9.5.2 – Authenticated (Subscriber+) Full Path Disclosure
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 5.9.5.2. This makes it possible for unauthenticated attackers to retrieve the full path of…
*-5.9.5.2
5.9.5.3
19/06/2025
ProfileGrid <= 5.9.5.2 – Authenticated (Subscriber+) Server-Side Request Forgery
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.9.5.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…
*-5.9.5.2
5.9.5.3
12/06/2025
ProfileGrid <= 5.9.5.1 – Missing Authorization
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.9.5.1. This makes it possible for…
*-5.9.5.1
5.9.5.2
16/05/2025
ProfileGrid <= 5.9.5.0 – Authenticated (Subscriber+) SQL Injection
The ProfileGrid plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.9.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
*-5.9.5.0
5.9.5.1
12/05/2025
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.