metagauss Vulnerabilities and Affected Products
Vulnerabilities associated with ProfileGrid.
Products
Clear product- ProfileGrid25 vulnerabilities
- ProfileGrid – User Profiles, Groups and Communities25 vulnerabilities
- RegistrationMagic21 vulnerabilities
- EventPrime – Events Calendar, Bookings and Tickets17 vulnerabilities
- EventPrime15 vulnerabilities
- RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login15 vulnerabilities
- Download Plugin3 vulnerabilities
- Download Theme1 vulnerability
- Event Kikfyre1 vulnerability
- Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-57697HIGH | WordPress ProfileGrid plugin <= 5.9.9.6 - Broken Authentication vulnerabilityAuthentication Bypass Using an Alternate Path or Channel vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Password Recovery Exploitation.This issue affects ProfileGrid : from n/a through <= 5.9.9.6. CWE-288Jul 13, 2026 | CVSS7.5v3.1 | EPSS0.319% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-57759HIGH | WordPress ProfileGrid plugin <= 5.9.9.7 - CSRF to Account Takeover vulnerabilityUnauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions. CWE-352Jul 2, 2026 | CVSS8.8v3.1 | EPSS0.142% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-25417MEDIUM | WordPress ProfileGrid plugin <= 5.9.8.1 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Stored XSS.This issue affects ProfileGrid : from n/a through <= 5.9.8.1. CWE-79Mar 25, 2026 | CVSS6.5v3.1 | EPSS0.156% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-4957HIGH | WordPress ProfileGrid plugin <= 5.9.5.7 - Reflected Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Reflected XSS.This issue affects ProfileGrid : from n/a through <= 5.9.5.7. CWE-79Sep 26, 2025 | CVSS7.1v3.1 | EPSS0.224% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-49033HIGH | WordPress ProfileGrid plugin <= 5.9.5.3 - SQL Injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Blind SQL Injection.This issue affects ProfileGrid : from n/a through <= 5.9.5.3. CWE-89Aug 14, 2025 | CVSS8.5v3.1 | EPSS0.261% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-49876HIGH | WordPress ProfileGrid plugin <= 5.9.5.2 - SQL Injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows SQL Injection.This issue affects ProfileGrid : from n/a through <= 5.9.5.2. CWE-89Jul 16, 2025 | CVSS8.5v3.1 | EPSS0.339% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-52719MEDIUM | WordPress ProfileGrid plugin <= 5.9.5.2 - Full Path Disclosure (FPD) VulnerabilityExposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Retrieve Embedded Sensitive Data.This issue affects ProfileGrid : from n/a through <= 5.9.5.2. CWE-497Jun 20, 2025 | CVSS4.3v3.1 | EPSS0.216% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-49877MEDIUM | WordPress ProfileGrid plugin <= 5.9.5.2 - Server Side Request Forgery (SSRF) VulnerabilityServer-Side Request Forgery (SSRF) vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Server Side Request Forgery.This issue affects ProfileGrid : from n/a through <= 5.9.5.2. CWE-918Jun 17, 2025 | CVSS4.9v3.1 | EPSS0.142% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-47478HIGH | WordPress ProfileGrid plugin <= 5.9.5.0 - SQL Injection VulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows SQL Injection.This issue affects ProfileGrid : from n/a through <= 5.9.5.0. CWE-89May 23, 2025 | CVSS8.5v3.1 | EPSS0.36% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-48079MEDIUM | WordPress ProfileGrid plugin <= 5.9.5.1 - Broken Access Control VulnerabilityMissing Authorization vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfileGrid : from n/a through <= 5.9.5.1. CWE-862May 16, 2025 | CVSS4.3v3.1 | EPSS0.216% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-39586HIGH | WordPress ProfileGrid plugin <= 5.9.4.8 - SQL Injection VulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows SQL Injection.This issue affects ProfileGrid : from n/a through <= 5.9.4.8. CWE-89Apr 17, 2025 | CVSS8.5v3.1 | EPSS0.323% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-26999HIGH | WordPress ProfileGrid Plugin <= 5.9.4.3 - PHP Object Injection vulnerabilityDeserialization of Untrusted Data vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Object Injection.This issue affects ProfileGrid : from n/a through <= 5.9.4.3. CWE-502Mar 3, 2025 | CVSS8.8v3.1 | EPSS0.678% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-49273MEDIUM | WordPress ProfileGrid plugin <= 5.9.3 - Cross Site Request Forgery (CSRF) vulnerabilityMissing Authorization vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities.This issue affects ProfileGrid : from n/a through <= 5.9.3. CWE-862Oct 21, 2024 | CVSS4.3v3.1 | EPSS0.305% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-6410MEDIUM | ProfileGrid <= 5.8.9 - Authenticated (Subscriber+) Insecure Direct Object ReferenceThe ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.8.9 via the 'pm_upload_image' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the profile picture of any user. CWE-639Jul 10, 2024 | CVSS4.3v3.1 | EPSS0.353% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-6411HIGH | ProfileGrid – User Profiles, Groups and Communities <= 5.8.9 - Authenticated (Subscriber+) Authorization Bypass to Privilege EscalationThe ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.8.9. This is due to a lack of validation on user-supplied data in the 'pm_upload_image' AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update their user capabilities to Administrator. CWE-269Jul 10, 2024 | CVSS8.8v3.1 | EPSS0.768% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-52117MEDIUM | WordPress ProfileGrid plugin <= 5.6.6 - Broken Access Control vulnerabilityMissing Authorization vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid: from n/a through 5.6.6. CWE-862Jun 12, 2024 | CVSS4.3v3.1 | EPSS0.296% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-32774MEDIUM | WordPress ProfileGrid plugin <= 5.8.2 - Group Members Limit Bypass vulnerabilityImproper Restriction of Excessive Authentication Attempts vulnerability in Metagauss ProfileGrid allows Removing Important Client Functionality.This issue affects ProfileGrid : from n/a through 5.8.2. CWE-307May 17, 2024 | CVSS4.3v3.1 | EPSS0.468% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-32772MEDIUM | WordPress ProfileGrid plugin <= 5.7.9 - Insecure Direct Object References (IDOR) vulnerabilityAuthorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9. CWE-639Apr 24, 2024 | CVSS4.3v3.1 | EPSS0.448% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-32808MEDIUM | WordPress ProfileGrid plugin <= 5.7.9 - Insecure Direct Object Reference (IDOR) vulnerabilityAuthorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9. CWE-639Apr 24, 2024 | CVSS5.4v3.1 | EPSS0.448% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-31362MEDIUM | WordPress ProfileGrid – User Profiles, Memberships, Groups and Communities plugin <= 5.7.8 - Cross Site Request Forgery (CSRF) vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8. CWE-352Apr 12, 2024 | CVSS4.3v3.1 | EPSS0.227% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-31291MEDIUM | WordPress ProfileGrid plugin <= 5.7.6 - IDOR on Friend Request vulnerabilityAuthorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.6. CWE-639Apr 7, 2024 | CVSS4.3v3.1 | EPSS0.379% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-30513MEDIUM | WordPress ProfileGrid plugin <= 5.7.2 - Insecure Direct Object References (IDOR) vulnerabilityAuthorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.2. CWE-639Mar 29, 2024 | CVSS6.5v3.1 | EPSS0.455% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-30491HIGH | WordPress ProfileGrid – User Profiles, Memberships, Groups and Communities plugin <= 5.7.8 - SQL Injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8. CWE-89Mar 29, 2024 | CVSS8.5v3.1 | EPSS32% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-30490CRITICAL | WordPress ProfileGrid plugin <= 5.7.8 - SQL Injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8. | CVSS9.3v3.1 | EPSS2.25% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-30241HIGH | WordPress ProfileGrid – User Profiles, Memberships, Groups and Communities plugin <= 5.7.1 - Contributor+ SQL Injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.1. CWE-89Mar 28, 2024 | CVSS8.5v3.1 | EPSS0.858% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |