Extension WordPress
Vulnérabilités ProfileGrid – User Profiles, Groups and Communities, page 3
Cette page rassemble les failles publiées pour ProfileGrid – User Profiles, Groups and Communities, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de ProfileGrid – User Profiles, Groups and Communities
56 fiches
ProfileGrid <= 5.7.6 – Authenticated (Subscriber+) Insecure Direct Object Reference
The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.7.6 due to missing validation on a user controlled key. This makes…
*-5.7.6
5.7.7
05/04/2024
ProfileGrid <= 5.7.8 – Unauthenticated SQL Injection
The ProfileGrid plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.7.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
*-5.7.8
5.7.9
28/03/2024
ProfileGrid <= 5.7.8 – Authenticated (Subscriber+) SQL Injection
The ProfileGrid plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.7.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
*-5.7.8
5.7.9
28/03/2024
ProfileGrid <= 5.7.2 – Authenticated (Subscriber+) Insecure Direct Object Reference
The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.7.2 due to missing validation on a user controlled key. This makes…
*-5.7.2
5.7.3
28/03/2024
ProfileGrid <= 5.6.6 – Missing Authorization
The ProfileGrid plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.6.6. This makes it possible for authenticated attackers, with subscriber-level access and above,…
*-5.6.6
5.6.7
28/12/2023
ProfileGrid <= 5.7.1 – Cross-Site Request Forgery
The ProfileGrid plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.7.1. This is due to missing nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform…
*-5.7.1
5.7.2
07/11/2023
ProfileGrid <= 5.5.1 – Missing Authorization to User Import
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pm_upload_csv' function in versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with subscriber-level…
*-5.5.1
5.5.2
17/07/2023
ProfileGrid <= 5.5.2 – Missing Authorization to Arbitrary Group Option Modification and Privilege Escalation
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'edit_group' handler in versions up to, and including, 5.5.2. This makes it possible for authenticated attackers, with group…
*-5.5.2
5.5.3
17/07/2023
ProfileGrid <= 5.5.0 – Hardcoded Encryption Key
The ProfileGrid plugin for WordPress is vulnerable to unauthorized decryption of private information in versions up to, and including, 5.5.0. This is due to the passphrase and iv being hardcoded in the 'pm_encrypt_decrypt_pass' function and used across all…
*-5.5.0
5.5.1
17/07/2023
ProfileGrid <= 5.5.1 – Authenticated (Subscriber+) Arbitrary Option Update
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'profile_magic_check_smtp_connection' function in versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with subscriber-level…
*-5.5.1
5.5.2
17/07/2023
ProfileGrid <= 5.3.0 – Missing Authorization to Arbitrary Password Reset
The ProfileGrid plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the pm_reset_user_password function in versions up to, and including, 5.3.0. This makes it possible for authenticated attackers, with subscriber-level access or…
*-5.3.0
5.3.1
27/02/2023
ProfileGrid <= 5.1.7 – Authenticated (Subscriber+) CSV Injection
The ProfileGrid plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 5.1.6, via the 'pm_get_csv_single_user_row' function. This allows subscriber-level attackers to embed untrusted input into exported CSV files, which can result in code…
*-5.1.7
5.1.8
17/11/2022
ProfileGrid – User Profiles, Memberships, Groups and Communities <= 5.0.3 – Missing Authorization to Information Exposure
The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when accessing messages in versions up to, and including, 5.0.3. This makes it possible for…
*-5.0.3
5.0.4
27/10/2022
ProfileGrid – User Profiles, Memberships, Groups and Communities <= 5.1.0 – Reflected Cross-Site Scripting
The ProfileGrid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in versions up to, and including, 5.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-5.1.0
5.1.1
19/10/2022
ProfileGrid – User Profiles, Memberships, Groups and Communities <= 4.7.4 – Stored Cross-Site Scripting via Profile
The ProfileGrid – User Profiles, Memberships, Groups and Communities WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the pm_user_avatar and pm_cover_image parameters found in the ~/admin/class-profile-magic-admin.php file which allows attackers with authenticated user…
*-4.7.4
4.7.7
18/01/2022
ProfileGrid – User Profiles, Memberships, Groups and Communities < 2.8.6 – Remote Code Execution
The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an wp-admin/admin-ajax.php request with the action=pm_template_preview&html=
[*, 2.8.6)
2.8.6
18/05/2018
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.