Extension WordPress

Vulnérabilités ProfileGrid – User Profiles, Groups and Communities, page 2

Cette page rassemble les failles publiées pour ProfileGrid – User Profiles, Groups and Communities, leurs plages de versions affectées et les correctifs signalés dans la base locale.

63Vulnérabilités
4Critiques
62Avec correctif
10,0CVSS maximal

Historique de sécurité

CVE et vulnérabilités de ProfileGrid – User Profiles, Groups and Communities

63 fiches

CVE-2025-6977 Moyenne · 6,1
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid – User Profiles, Groups and Communities <= 5.9.5.4 – Reflected Cross-Site Scripting via 'pm_get_messenger_notification' function

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘pm_get_messenger_notification’ function in all versions up to, and including, 5.9.5.4 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-5.9.5.4

Correctif

5.9.5.5

Publication

15/07/2025

CVE-2025-52719 Moyenne · 4,3
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid <= 5.9.5.2 – Authenticated (Subscriber+) Full Path Disclosure

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 5.9.5.2. This makes it possible for unauthenticated attackers to retrieve the full path of…

Versions affectées

*-5.9.5.2

Correctif

5.9.5.3

Publication

19/06/2025

CVE-2025-49877 Moyenne · 6,4
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid <= 5.9.5.2 – Authenticated (Subscriber+) Server-Side Request Forgery

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.9.5.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…

Versions affectées

*-5.9.5.2

Correctif

5.9.5.3

Publication

12/06/2025

CVE-2025-0724 Élevée · 8,8
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.5 – Authenticated (Subscriber+) PHP Object Injection

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.4.5 via deserialization of untrusted input in the get_user_meta_fields_html function. This makes it possible…

Versions affectées

*-5.9.4.5

Correctif

5.9.4.6

Publication

21/03/2025

CVE-2025-1408 Moyenne · 4,3
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.4 – Missing Authorinzation to Authenticated (Subscriber+) Join Group Requests Management

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_decline_join_group_request and pm_approve_join_group_request functions in all versions up to, and including, 5.9.4.4.…

Versions affectées

*-5.9.4.4

Correctif

5.9.4.5

Publication

21/03/2025

CVE-2025-0723 Moyenne · 6,5
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.7 – Authenticated (Subscriber+) SQL Injection

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind and time-based SQL Injections via the rid and search parameters in all versions up to, and including, 5.9.4.7 due to insufficient escaping on…

Versions affectées

*-5.9.4.7

Correctif

5.9.4.8

Publication

21/03/2025

CVE-2025-26999 Élevée · 8,8
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid <= 5.9.4.3 – Authenticated (Subscriber+) PHP Object Injection

The ProfileGrid plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.9.4.3 via deserialization of untrusted input. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a…

Versions affectées

*-5.9.4.3

Correctif

5.9.4.4

Publication

23/02/2025

CVE-2024-13740 Moyenne · 4,3
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.2 – Insecure Direct Object Reference to Authenticated (Subscriber+) Private Messages Disclosure

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.4.2 via the pm_messenger_show_messages function due to missing validation on a user controlled…

Versions affectées

*-5.9.4.2

Correctif

5.9.4.3

Publication

17/02/2025

CVE-2024-13741 Moyenne · 5,4
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.2 – Authenticated (Subscriber+) Limited Server-Side Request Forgery

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 5.9.4.2 via the pm_upload_image function. This makes it possible for authenticated attackers, with…

Versions affectées

*-5.9.4.2

Correctif

5.9.4.3

Publication

17/02/2025

CVE-2024-10900 Moyenne · 6,5
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid – User Profiles, Groups and Communities <= 5.9.3.6 – Missing Authorization to Authenticated (Subscriber+) Arbitrary User Meta Deletion

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_remove_file_attachment() function in all versions up to, and including, 5.9.3.6. This makes…

Versions affectées

*-5.9.3.6

Correctif

5.9.3.7

Publication

19/11/2024

CVE-2024-49273 Moyenne · 4,3
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid <= 5.9.3 – Cross-Site Request Forgery

The ProfileGrid plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.9.3. This is due to missing or incorrect nonce validation on the pg_create_group_page() function. This makes it possible for unauthenticated attackers…

Versions affectées

*-5.9.3

Correctif

5.9.3.1

Publication

14/10/2024

CVE-2024-8861 Moyenne · 6,4
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid – User Profiles, Groups and Communities <= 5.9.3.2 – Authenticated (Contributor+) Stored Cross-Site Scripting

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.9.3.2 due to incorrect use of the wp_kses_allowed_html function, which allows the 'onclick' attribute…

Versions affectées

*-5.9.3.2

Correctif

5.9.3.3

Publication

25/09/2024

CVE-2024-6410 Moyenne · 4,3
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid <= 5.8.9 – Authenticated (Subscriber+) Insecure Direct Object Reference

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.8.9 via the 'pm_upload_image' function due to missing validation on a user controlled…

Versions affectées

*-5.8.9

Correctif

5.9.0

Publication

09/07/2024

CVE-2024-6411 Élevée · 8,8
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid – User Profiles, Groups and Communities <= 5.8.9 – Authenticated (Subscriber+) Authorization Bypass to Privilege Escalation

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.8.9. This is due to a lack of validation on user-supplied data in the 'pm_upload_image'…

Versions affectées

*-5.8.9

Correctif

5.9.0

Publication

09/07/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités