CVE-2026-1271
MEDIUMProfileGrid - User Profiles, Groups and Communities <5.9.7.2 - Inse...
Title source: llmDescription
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.7.2 via the 'pm_upload_image' and 'pm_upload_cover_image' AJAX actions. This is due to the update_user_meta() function being called outside of the user authorization check in public/partials/crop.php and public/partials/coverimg_crop.php. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change any user's profile picture or cover image, including administrators.
References (6)
Core 6
Core References
Scores
CVSS v3
5.3
EPSS
0.0032
EPSS Percentile
23.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-639
Status
published
Products (1)
metagauss/ProfileGrid – User Profiles, Groups and Communities
< 5.9.7.2
Published
Feb 05, 2026
Tracked Since
Feb 18, 2026