HomeWordPress vulnerabilitiesProfileGrid
ProfileGrid vulnerabilities
ProfileGrid has 38 known vulnerabilities in this database. The most recent published record is dated 1 Oct 2026.
- Known vulnerabilities
- 38
- Active installs
- 5,000+
- Latest version
- 6.0.0.3
- Last updated
- 30 Sep 2026
- Most recent
- 1 Oct 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Broken access control CVE-2026-62061 | Medium 5.3 | Up to 6.0.0.2 | Fixed in a later version (latest 6.0.0.3) | 6 d ago |
| Broken access control CVE-2026-16290 | Medium 5.3 | Before 6.0.0.0 | Fixed in 6.0.0.0 | 6 Aug 2026 |
| Broken access control CVE-2026-16289 | Medium 4.3 | Before 6.0.0.0 | Fixed in 6.0.0.0 | 3 Aug 2026 |
| Broken access control CVE-2026-16291 | Medium 4.3 | Before 5.9.9.8 | Fixed in 5.9.9.8 | 2 Aug 2026 |
| Privilege escalation CVE-2026-12687 | High 7.5 | Before 5.9.9.8 | Fixed in 5.9.9.8 | 30 Jul 2026 |
| Broken access control CVE-2026-12688 | Medium 6.5 | Before 5.9.9.7 | Fixed in 5.9.9.7 | 24 Jul 2026 |
| Broken access control CVE-2026-12689 | Medium 5.4 | Before 5.9.9.7 | Fixed in 5.9.9.7 | 24 Jul 2026 |
| Broken access control CVE-2026-12690 | Low 3.8 | Before 5.9.9.7 | Fixed in 5.9.9.7 | 24 Jul 2026 |
| Privilege escalation CVE-2026-12073 | Critical 9.8 | Up to 5.9.9.5 | Fixed in a later version (latest 6.0.0.3) | 30 Jun 2026 |
| Cross-site scripting (XSS) CVE-2026-4610 | Medium 6.4 | Up to 5.9.9.2 | Fixed in a later version (latest 6.0.0.3) | 23 Jun 2026 |
| Broken access control CVE-2026-4607 | Medium 4.3 | Up to 5.9.8.4 | Fixed in a later version (latest 6.0.0.3) | 13 May 2026 |
| SQL injection CVE-2026-4608 | Medium 6.5 | Up to 5.9.8.4 | Fixed in a later version (latest 6.0.0.3) | 13 May 2026 |
| Broken access control CVE-2026-4609 | High 7.1 | Up to 5.9.8.4 | Fixed in a later version (latest 6.0.0.3) | 13 May 2026 |
| Broken access control CVE-2026-2488 | Medium 4.3 | Up to 5.9.8.1 | Fixed in a later version (latest 6.0.0.3) | 7 Mar 2026 |
| Cross-site request forgery (CSRF) CVE-2026-2494 | Medium 4.3 | Up to 5.9.8.2 | Fixed in a later version (latest 6.0.0.3) | 7 Mar 2026 |
| Broken access control CVE-2026-1271 | Medium 5.3 | Up to 5.9.7.2 | Fixed in a later version (latest 6.0.0.3) | 5 Feb 2026 |
| Broken access control CVE-2025-13416 | Medium 4.3 | Up to 5.9.7.2 | Fixed in a later version (latest 6.0.0.3) | 5 Feb 2026 |
| Cross-site scripting (XSS) CVE-2025-6977 | Medium 6.1 | Before 5.9.5.5 | Fixed in 5.9.5.5 | 16 Jul 2025 |
| SQL injection CVE-2025-0723 | Medium 6.5 | Before 5.9.4.8 | Fixed in 5.9.4.8 | 22 Mar 2025 |
| PHP object injection CVE-2025-0724 | High 8.8 | Before 5.9.4.6 | Fixed in 5.9.4.6 | 22 Mar 2025 |
| Broken access control CVE-2025-1408 | Medium 4.3 | Before 5.9.4.5 | Fixed in 5.9.4.5 | 22 Mar 2025 |
| Broken access control CVE-2024-13740 | Medium 4.3 | Before 5.9.4.3 | Fixed in 5.9.4.3 | 18 Feb 2025 |
| Server-side request forgery (SSRF) CVE-2024-13741 | Medium 5.4 | Before 5.9.4.3 | Fixed in 5.9.4.3 | 18 Feb 2025 |
| Broken access control CVE-2024-10900 | Medium 6.5 | Before 5.9.3.7 | Fixed in 5.9.3.7 | 20 Nov 2024 |
| Cross-site scripting (XSS) CVE-2024-8861 | Medium 6.4 | Before 5.9.3.3 | Fixed in 5.9.3.3 | 26 Sep 2024 |
| Broken access control CVE-2024-6410 | Medium 4.3 | Before 5.9.0 | Fixed in 5.9.0 | 10 Jul 2024 |
| Privilege escalation CVE-2024-6411 | High 8.8 | Before 5.9.0 | Fixed in 5.9.0 | 10 Jul 2024 |
| Broken access control CVE-2024-5453 | Medium 4.3 | Before 5.8.7 | Fixed in 5.8.7 | 5 Jun 2024 |
| Broken access control CVE-2024-3606 | Medium 4.3 | Before 5.8.4 | Fixed in 5.8.4 | 2 May 2024 |
| Broken access control CVE-2023-3404 | Medium 4.9 | Up to 5.5.0 | Fixed in a later version (latest 6.0.0.3) | 31 Aug 2023 |
| Privilege escalation CVE-2023-3713 | High 8.8 | Up to 5.5.1 | Fixed in a later version (latest 6.0.0.3) | 18 Jul 2023 |
| Privilege escalation CVE-2023-3714 | High 7.5 | Before 5.5.3 | Fixed in 5.5.3 | 18 Jul 2023 |
| Broken access control CVE-2023-3403 | Medium 5.4 | Up to 5.5.1 | Fixed in a later version (latest 6.0.0.3) | 18 Jul 2023 |
| Broken access control CVE-2023-0940 | High 8.8 | Before 5.3.1 | Fixed in 5.3.1 | 20 Mar 2023 |
| CSV injection CVE-2022-41791 | Medium 6.8 | Up to 5.1.6 | Fixed in a later version (latest 6.0.0.3) | 17 Nov 2022 |
| Cross-site scripting (XSS) CVE-2022-3578 | Medium 6.1 | Before 5.1.1 | Fixed in 5.1.1 | 14 Nov 2022 |
| Cross-site scripting (XSS) CVE-2022-0233 | Medium 6.4 | Up to 4.7.4 | Fixed in a later version (latest 6.0.0.3) | 18 Jan 2022 |
| Remote code execution CVE-2019-15873 | High 8.8 | Before 2.8.6 | Fixed in 2.8.6 | 3 Sep 2019 |
Read the published descriptions
- CVE-2026-62061, 1 Oct 2026
- Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfileGrid: from n/a through 6.0.0.2. CVE record
- CVE-2026-16290, 6 Aug 2026
- The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list, and registers the handler for unauthenticated users, allowing any unauthenticated visitor to disclose the members and their identifiers of any group, including private or closed ones, bypassing the ProfileGrid WordPress plugin before 6.0.0.0's member-visibility setting. CVE record
- CVE-2026-16289, 3 Aug 2026
- The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user such as a Subscriber to disclose the names and request dates of the users awaiting approval to join any group, including private ones. CVE record
- CVE-2026-16291, 2 Aug 2026
- The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user before deleting it, allowing any authenticated user such as a Subscriber to delete other users' notifications by enumerating notification identifiers. CVE record
- CVE-2026-12687, 30 Jul 2026
- The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into through its front-end registration, allowing unauthenticated users to register directly into a privileged group and be granted that group's configured role, up to Administrator when such a group exists, leading to privilege escalation. CVE record
- CVE-2026-12688, 24 Jul 2026
- The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group membership, allowing unauthenticated attackers to forge a payment notification and mark any user as a paid member of any group without any payment being made. CVE record
- CVE-2026-12689, 24 Jul 2026
- The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions, allowing authenticated users with Subscriber-level access and above to soft-delete, tamper with the metadata of, and mark as read other users' private message threads. CVE record
- CVE-2026-12690, 24 Jul 2026
- The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its license management actions, relying only on a nonce that is exposed to any logged-in user, allowing authenticated users with Subscriber-level access and above to overwrite the site's premium license settings. CVE record
- CVE-2026-12073, 30 Jun 2026
- The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.9.9.5. This is due to the plugin not validating a `user_login` on registration forms that don't contain this parameter, and not properly handling the error messages. This makes it possible for unauthenticated attackers to change email address of user account with ID=1 (usually an administrator), and leverage that to reset the user's password and gain access to their account. CVE record
- CVE-2026-4610, 23 Jun 2026
- The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pm_author_message' parameter in the pm_send_message_to_author function in all versions up to, and including, 5.9.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 5.9.8.5. CVE record
- CVE-2026-4607, 13 May 2026
- The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.9.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action via the pm_set_group_order, pm_set_group_items, and pm_set_field_order AJAX actions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify site-wide ProfileGrid group settings including group menu order, group list order, group icon display, and field ordering. CVE record
- CVE-2026-4608, 13 May 2026
- The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind SQL Injection via the 'rid' parameter in all versions up to, and including, 5.9.8.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2026-4609, 13 May 2026
- The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the pm_invite_user function in all versions up to, and including, 5.9.8.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to add themselves or any registered user to any ProfileGrid group, including closed and paid groups, bypassing all authorization and payment gates. CVE record
- CVE-2026-2488, 7 Mar 2026
- The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized message deletion due to a missing capability check on the pg_delete_msg() function in all versions up to, and including, 5.9.8.1. This is due to the function not verifying that the requesting user has permission to delete the targeted message. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary messages belonging to any user by sending a direct request with a valid message ID (mid parameter). CVE record
- CVE-2026-2494, 7 Mar 2026
- The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.9.8.2. This is due to missing nonce validation on the membership request management page (approve and decline actions). This makes it possible for unauthenticated attackers to approve or deny group membership requests via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
- CVE-2026-1271, 5 Feb 2026
- The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.7.2 via the 'pm_upload_image' and 'pm_upload_cover_image' AJAX actions. This is due to the update_user_meta() function being called outside of the user authorization check in public/partials/crop.php and public/partials/coverimg_crop.php. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change any user's profile picture or cover image, including administrators. CVE record
- CVE-2025-13416, 5 Feb 2026
- The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized user suspension due to a missing capability check on the pm_deactivate_user_from_group() function in all versions up to, and including, 5.9.7.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to suspend arbitrary users from groups, including administrators, via the pm_deactivate_user_from_group AJAX action. CVE record
- CVE-2025-6977, 16 Jul 2025
- The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘pm_get_messenger_notification’ function in all versions up to, and including, 5.9.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a logged-in user into performing an action such as clicking on a link. CVE record
- CVE-2025-0723, 22 Mar 2025
- The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind and time-based SQL Injections via the rid and search parameters in all versions up to, and including, 5.9.4.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2025-0724, 22 Mar 2025
- The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.4.5 via deserialization of untrusted input in the get_user_meta_fields_html function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. CVE record
- CVE-2025-1408, 22 Mar 2025
- The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_decline_join_group_request and pm_approve_join_group_request functions in all versions up to, and including, 5.9.4.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to approve or decline join group requests which is normally should be available to administrators only. CVE record
- CVE-2024-13740, 18 Feb 2025
- The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.4.2 via the pm_messenger_show_messages function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read private conversations of other users. CVE record
- CVE-2024-13741, 18 Feb 2025
- The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 5.9.4.2 via the pm_upload_image function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to download and view images, as well as validating if a non-image file exists, both on local or remote hosts. CVE record
- CVE-2024-10900, 20 Nov 2024
- The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_remove_file_attachment() function in all versions up to, and including, 5.9.3.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary user meta which can do things like deny an administrator's access to their site. . CVE record
- CVE-2024-8861, 26 Sep 2024
- The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.9.3.2 due to incorrect use of the wp_kses_allowed_html function, which allows the 'onclick' attribute for certain HTML elements without sufficient restriction or context validation. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-6410, 10 Jul 2024
- The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.8.9 via the 'pm_upload_image' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the profile picture of any user. CVE record
- CVE-2024-6411, 10 Jul 2024
- The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.8.9. This is due to a lack of validation on user-supplied data in the 'pm_upload_image' AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update their user capabilities to Administrator. CVE record
- CVE-2024-5453, 5 Jun 2024
- The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_dismissible_notice and pm_wizard_update_group_icon functions in all versions up to, and including, 5.8.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary options to the value '1' or change group icons. CVE record
- CVE-2024-3606, 2 May 2024
- The ProfileGrid - User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the pm_upload_cover_image function in all versions up to, and including, 5.8.3. This makes it possible for authenticated attackers, with subscriber access or higher, to delete attachments. CVE record
- CVE-2023-3404, 31 Aug 2023
- The ProfileGrid plugin for WordPress is vulnerable to unauthorized decryption of private information in versions up to, and including, 5.5.0. This is due to the passphrase and iv being hardcoded in the 'pm_encrypt_decrypt_pass' function and used across all sites running the plugin. This makes it possible for authenticated attackers, with administrator-level permissions or above to decrypt and view users' passwords. If combined with another vulnerability, this can potentially grant lower-privileged users access to users' passwords. CVE record
- CVE-2023-3713, 18 Jul 2023
- The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'profile_magic_check_smtp_connection' function in versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update the site options arbitrarily. This can be used by attackers to achieve privilege escalation. CVE record
- CVE-2023-3714, 18 Jul 2023
- The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'edit_group' handler in versions up to, and including, 5.5.2. This makes it possible for authenticated attackers, with group ownership, to update group options, including the 'associate_role' parameter, which defines the member's role. This issue was partially patched in version 5.5.2 preventing privilege escalation, however, it was fully patched in 5.5.3. CVE record
- CVE-2023-3403, 18 Jul 2023
- The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pm_upload_csv' function in versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with subscriber-level permissions or above to import new users and update existing users. CVE record
- CVE-2023-0940, 20 Mar 2023
- The ProfileGrid WordPress plugin before 5.3.1 provides an AJAX endpoint for resetting a user password but does not implement proper authorization. This allows a user with low privileges, such as subscriber, to change the password of any account, including Administrator ones. CVE record
- CVE-2022-41791, 17 Nov 2022
- Auth. (subscriber+) CSV Injection vulnerability in ProfileGrid plugin <= 5.1.6 on WordPress. CVE record
- CVE-2022-3578, 14 Nov 2022
- The ProfileGrid WordPress plugin before 5.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting CVE record
- CVE-2022-0233, 18 Jan 2022
- The ProfileGrid - User Profiles, Memberships, Groups and Communities WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the pm_user_avatar and pm_cover_image parameters found in the ~/admin/class-profile-magic-admin.php file which allows attackers with authenticated user access, such as subscribers, to inject arbitrary web scripts into their profile, in versions up to and including 1.2.7. CVE record
- CVE-2019-15873, 3 Sep 2019
- The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an wp-admin/admin-ajax.php request with the action=pm_template_preview&html=<?php substring followed by PHP code. CVE record
What to do if you run ProfileGrid
If you run ProfileGrid, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new ProfileGrid vulnerabilities
Free. We email you when a new vulnerability is published for ProfileGrid, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.