Extension WordPress
Vulnérabilités ProfileGrid – User Profiles, Groups and Communities, page 2
Cette page rassemble les failles publiées pour ProfileGrid – User Profiles, Groups and Communities, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de ProfileGrid – User Profiles, Groups and Communities
56 fiches
ProfileGrid <= 5.9.4.8 – Authenticated (Subscriber+) SQL Injection
The ProfileGrid plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.9.4.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
*-5.9.4.8
5.9.4.9
17/04/2025
ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.5 – Authenticated (Subscriber+) PHP Object Injection
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.4.5 via deserialization of untrusted input in the get_user_meta_fields_html function. This makes it possible…
*-5.9.4.5
5.9.4.6
21/03/2025
ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.4 – Missing Authorinzation to Authenticated (Subscriber+) Join Group Requests Management
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_decline_join_group_request and pm_approve_join_group_request functions in all versions up to, and including, 5.9.4.4.…
*-5.9.4.4
5.9.4.5
21/03/2025
ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.7 – Authenticated (Subscriber+) SQL Injection
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind and time-based SQL Injections via the rid and search parameters in all versions up to, and including, 5.9.4.7 due to insufficient escaping on…
*-5.9.4.7
5.9.4.8
21/03/2025
ProfileGrid <= 5.9.4.3 – Authenticated (Subscriber+) PHP Object Injection
The ProfileGrid plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.9.4.3 via deserialization of untrusted input. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a…
*-5.9.4.3
5.9.4.4
23/02/2025
ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.2 – Insecure Direct Object Reference to Authenticated (Subscriber+) Private Messages Disclosure
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.4.2 via the pm_messenger_show_messages function due to missing validation on a user controlled…
*-5.9.4.2
5.9.4.3
17/02/2025
ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.2 – Authenticated (Subscriber+) Limited Server-Side Request Forgery
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 5.9.4.2 via the pm_upload_image function. This makes it possible for authenticated attackers, with…
*-5.9.4.2
5.9.4.3
17/02/2025
ProfileGrid – User Profiles, Groups and Communities <= 5.9.3.6 – Missing Authorization to Authenticated (Subscriber+) Arbitrary User Meta Deletion
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_remove_file_attachment() function in all versions up to, and including, 5.9.3.6. This makes…
*-5.9.3.6
5.9.3.7
19/11/2024
ProfileGrid <= 5.9.3 – Cross-Site Request Forgery
The ProfileGrid plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.9.3. This is due to missing or incorrect nonce validation on the pg_create_group_page() function. This makes it possible for unauthenticated attackers…
*-5.9.3
5.9.3.1
14/10/2024
ProfileGrid – User Profiles, Groups and Communities <= 5.9.3.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.9.3.2 due to incorrect use of the wp_kses_allowed_html function, which allows the 'onclick' attribute…
*-5.9.3.2
5.9.3.3
25/09/2024
ProfileGrid <= 5.8.9 – Authenticated (Subscriber+) Insecure Direct Object Reference
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.8.9 via the 'pm_upload_image' function due to missing validation on a user controlled…
*-5.8.9
5.9.0
09/07/2024
ProfileGrid – User Profiles, Groups and Communities <= 5.8.9 – Authenticated (Subscriber+) Authorization Bypass to Privilege Escalation
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.8.9. This is due to a lack of validation on user-supplied data in the 'pm_upload_image'…
*-5.8.9
5.9.0
09/07/2024
ProfileGrid <= 5.8.7 – Missing Authorization
The ProfileGrid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the pm_create_message function in versions up to, and including, 5.8.7. This makes it possible for authenticated attackers, with subscriber-level access and…
*-5.8.7
5.8.8
01/07/2024
ProfileGrid <= 5.8.6 – Missing Authorization
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_dismissible_notice and pm_wizard_update_group_icon functions in all versions up to, and including, 5.8.6.…
*-5.8.6
5.8.7
04/06/2024
ProfileGrid <= 5.7.1 – Authenticated (Contributor+) SQL Injection
The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 5.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient…
*-5.7.1
5.7.2
26/04/2024
ProfileGrid – User Profiles, Memberships, Groups and Communities <= 5.7.9 – Insecure Direct Object Reference
The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.7.9 due to missing validation on a user controlled key. This makes…
*-5.7.9
5.8.0
22/04/2024
ProfileGrid <= 5.8.2 – Bypass Group Members Limit
The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to group limit bypass in all versions up to, and including, 5.8.2. This is due to the plugin not properly verifying the limits of…
*-5.8.2
5.8.3
22/04/2024
ProfileGrid – User Profiles, Memberships, Groups and Communities <= 5.7.9 – Insecure Direct Object Reference
The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.7.9 due to missing validation on a user controlled key in the…
*-5.7.9
5.8.0
22/04/2024
ProfileGrid – User Profiles, Memberships, Groups and Communities <= 5.8.3 – Missing Authorization
The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the pm_upload_cover_image function in all versions up to, and including, 5.8.3. This…
*-5.8.3
5.8.4
16/04/2024
ProfileGrid <= 5.7.8 – Cross-Site Request Forgery
The ProfileGrid plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.7.8. This is due to missing or incorrect nonce validation in the admin/partials/add-group.php file. This makes it possible for unauthenticated attackers…
*-5.7.8
5.7.9
08/04/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.