Home/Product/metagauss profilegrid
Product

metagauss profilegrid

35 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-6977
< 5.9.5.5
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t
6.1MEDIUM
CVE-2025-1408
< 5.9.4.5
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data du
4.3MEDIUM
CVE-2025-0724
< 5.9.4.6
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to PHP Object Injection in all versions
8.8HIGH
CVE-2025-0723
< 5.9.4.8
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind and time-based SQL Injections
6.5MEDIUM
CVE-2024-13740
< 5.9.4.3
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in
4.3MEDIUM
CVE-2024-13741
< 5.9.4.3
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to Limited Server-Side Request Forgery
5.4MEDIUM
CVE-2024-10900
< 5.9.3.7
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data du
6.5MEDIUM
CVE-2024-37453
< 5.8.8
Missing Authorization vulnerability in ProfileGrid User Profiles ProfileGrid allows Exploiting Incorrectly Configured Access Contr
4.3MEDIUM
CVE-2024-49273
<= 5.9.3
Missing Authorization vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities.This issue affects
4.3MEDIUM
CVE-2024-8861
< 5.9.3.3
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all v
6.4MEDIUM
CVE-2024-6411
< 5.9.0
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation in all versions
8.8HIGH
CVE-2024-6410
< 5.9.0
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in
4.3MEDIUM
CVE-2023-52117
< 5.6.7
Missing Authorization vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid: from n/a through 5.6.6.
4.3MEDIUM
CVE-2024-5453
< 5.8.7
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data du
4.3MEDIUM
CVE-2024-32774
< 5.8.3
Improper Restriction of Excessive Authentication Attempts vulnerability in Metagauss ProfileGrid allows Removing Important Client
4.3MEDIUM
CVE-2024-3606
< 5.8.4
The ProfileGrid - User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to unauthorized deletion o
4.3MEDIUM
CVE-2024-32808
< 5.8.0
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a
5.4MEDIUM
CVE-2024-32772
< 5.8.0
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a
4.3MEDIUM
CVE-2024-31362
< 5.7.9
Cross-Site Request Forgery (CSRF) vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8.
4.3MEDIUM
CVE-2024-31291
< 5.7.7
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a
4.3MEDIUM
CVE-2024-30513
< 5.7.3
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a
6.5MEDIUM
CVE-2024-30491
< 5.7.9
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This i
8.5HIGH
CVE-2024-30490
< 5.7.9
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This i
9.3CRITICAL
CVE-2024-30241
< 5.7.2
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This i
8.5HIGH
CVE-2022-36352
<= 5.0.3
Missing Authorization vulnerability in Profilegrid - User Profiles, Memberships, Groups and Communities.This issue aff
6.3MEDIUM
CVE-2023-47644
<= 5.6.6
Cross-Site Request Forgery (CSRF) vulnerability in profilegrid - User Profiles, Memberships, Groups and Communities.Th
5.4MEDIUM
CVE-2023-3404
<= 5.5.0
The ProfileGrid plugin for WordPress is vulnerable to unauthorized decryption of private information in versions up to, and includ
4.9MEDIUM
CVE-2023-3714
< 5.5.3
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '
7.5HIGH
CVE-2023-3713
<= 5.5.1
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '
8.8HIGH
CVE-2023-3403
<= 5.5.1
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the '
5.4MEDIUM
CVE-2023-0940
< 5.3.1
The ProfileGrid WordPress plugin before 5.3.1 provides an AJAX endpoint for resetting a user password but does not implement prope
8.8HIGH
CVE-2022-41791
<= 5.1.6
Auth. (subscriber+) CSV Injection vulnerability in ProfileGrid plugin <= 5.1.6 on WordPress.
6.8MEDIUM
CVE-2022-3578
< 5.1.1
The ProfileGrid WordPress plugin before 5.1.1 does not sanitise and escape a parameter before outputting it back in the page, lead
6.1MEDIUM
CVE-2022-0233
<= 4.7.4
The ProfileGrid - User Profiles, Memberships, Groups and Communities WordPress plugin is vulnerable to Stored Cross-Site Scripting
6.4MEDIUM
CVE-2019-15873
< 2.8.6
The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an wp-admin/a
8.8HIGH
threatengine.sh