Extension WordPress

Vulnérabilités ProfileGrid – User Profiles, Groups and Communities, page 2

Cette page rassemble les failles publiées pour ProfileGrid – User Profiles, Groups and Communities, leurs plages de versions affectées et les correctifs signalés dans la base locale.

56Vulnérabilités
4Critiques
55Avec correctif
10,0CVSS maximal

Historique de sécurité

CVE et vulnérabilités de ProfileGrid – User Profiles, Groups and Communities

56 fiches

CVE-2025-0724 Élevée · 8,8
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.5 – Authenticated (Subscriber+) PHP Object Injection

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.4.5 via deserialization of untrusted input in the get_user_meta_fields_html function. This makes it possible…

Versions affectées

*-5.9.4.5

Correctif

5.9.4.6

Publication

21/03/2025

CVE-2025-1408 Moyenne · 4,3
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.4 – Missing Authorinzation to Authenticated (Subscriber+) Join Group Requests Management

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_decline_join_group_request and pm_approve_join_group_request functions in all versions up to, and including, 5.9.4.4.…

Versions affectées

*-5.9.4.4

Correctif

5.9.4.5

Publication

21/03/2025

CVE-2025-0723 Moyenne · 6,5
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.7 – Authenticated (Subscriber+) SQL Injection

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind and time-based SQL Injections via the rid and search parameters in all versions up to, and including, 5.9.4.7 due to insufficient escaping on…

Versions affectées

*-5.9.4.7

Correctif

5.9.4.8

Publication

21/03/2025

CVE-2025-26999 Élevée · 8,8
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid <= 5.9.4.3 – Authenticated (Subscriber+) PHP Object Injection

The ProfileGrid plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.9.4.3 via deserialization of untrusted input. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a…

Versions affectées

*-5.9.4.3

Correctif

5.9.4.4

Publication

23/02/2025

CVE-2024-13740 Moyenne · 4,3
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.2 – Insecure Direct Object Reference to Authenticated (Subscriber+) Private Messages Disclosure

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.4.2 via the pm_messenger_show_messages function due to missing validation on a user controlled…

Versions affectées

*-5.9.4.2

Correctif

5.9.4.3

Publication

17/02/2025

CVE-2024-13741 Moyenne · 5,4
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.2 – Authenticated (Subscriber+) Limited Server-Side Request Forgery

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 5.9.4.2 via the pm_upload_image function. This makes it possible for authenticated attackers, with…

Versions affectées

*-5.9.4.2

Correctif

5.9.4.3

Publication

17/02/2025

CVE-2024-10900 Moyenne · 6,5
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid – User Profiles, Groups and Communities <= 5.9.3.6 – Missing Authorization to Authenticated (Subscriber+) Arbitrary User Meta Deletion

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_remove_file_attachment() function in all versions up to, and including, 5.9.3.6. This makes…

Versions affectées

*-5.9.3.6

Correctif

5.9.3.7

Publication

19/11/2024

CVE-2024-49273 Moyenne · 4,3
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid <= 5.9.3 – Cross-Site Request Forgery

The ProfileGrid plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.9.3. This is due to missing or incorrect nonce validation on the pg_create_group_page() function. This makes it possible for unauthenticated attackers…

Versions affectées

*-5.9.3

Correctif

5.9.3.1

Publication

14/10/2024

CVE-2024-8861 Moyenne · 6,4
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid – User Profiles, Groups and Communities <= 5.9.3.2 – Authenticated (Contributor+) Stored Cross-Site Scripting

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.9.3.2 due to incorrect use of the wp_kses_allowed_html function, which allows the 'onclick' attribute…

Versions affectées

*-5.9.3.2

Correctif

5.9.3.3

Publication

25/09/2024

CVE-2024-6410 Moyenne · 4,3
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid <= 5.8.9 – Authenticated (Subscriber+) Insecure Direct Object Reference

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.8.9 via the 'pm_upload_image' function due to missing validation on a user controlled…

Versions affectées

*-5.8.9

Correctif

5.9.0

Publication

09/07/2024

CVE-2024-6411 Élevée · 8,8
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid – User Profiles, Groups and Communities <= 5.8.9 – Authenticated (Subscriber+) Authorization Bypass to Privilege Escalation

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.8.9. This is due to a lack of validation on user-supplied data in the 'pm_upload_image'…

Versions affectées

*-5.8.9

Correctif

5.9.0

Publication

09/07/2024

CVE-2024-5453 Moyenne · 4,3
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid <= 5.8.6 – Missing Authorization

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_dismissible_notice and pm_wizard_update_group_icon functions in all versions up to, and including, 5.8.6.…

Versions affectées

*-5.8.6

Correctif

5.8.7

Publication

04/06/2024

CVE-2024-32772 Moyenne · 4,3
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid – User Profiles, Memberships, Groups and Communities <= 5.7.9 – Insecure Direct Object Reference

The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.7.9 due to missing validation on a user controlled key. This makes…

Versions affectées

*-5.7.9

Correctif

5.8.0

Publication

22/04/2024

CVE-2024-32808 Moyenne · 4,3
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid – User Profiles, Memberships, Groups and Communities <= 5.7.9 – Insecure Direct Object Reference

The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.7.9 due to missing validation on a user controlled key in the…

Versions affectées

*-5.7.9

Correctif

5.8.0

Publication

22/04/2024

CVE-2024-3606 Moyenne · 4,3
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid – User Profiles, Memberships, Groups and Communities <= 5.8.3 – Missing Authorization

The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the pm_upload_cover_image function in all versions up to, and including, 5.8.3. This…

Versions affectées

*-5.8.3

Correctif

5.8.4

Publication

16/04/2024

CVE-2024-31362 Moyenne · 4,3
ProfileGrid – User Profiles, Groups and Communities

ProfileGrid <= 5.7.8 – Cross-Site Request Forgery

The ProfileGrid plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.7.8. This is due to missing or incorrect nonce validation in the admin/partials/add-group.php file. This makes it possible for unauthenticated attackers…

Versions affectées

*-5.7.8

Correctif

5.7.9

Publication

08/04/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités