Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesProfileGrid

ProfileGrid vulnerabilities

ProfileGrid has 38 known vulnerabilities in this database. The most recent published record is dated 1 Oct 2026.

Known vulnerabilities
38
Active installs
5,000+
Latest version
6.0.0.3
Last updated
30 Sep 2026
Most recent
1 Oct 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Broken access control
CVE-2026-62061
Medium 5.3Up to 6.0.0.2Fixed in a later version (latest 6.0.0.3)6 d ago
Broken access control
CVE-2026-16290
Medium 5.3Before 6.0.0.0Fixed in 6.0.0.06 Aug 2026
Broken access control
CVE-2026-16289
Medium 4.3Before 6.0.0.0Fixed in 6.0.0.03 Aug 2026
Broken access control
CVE-2026-16291
Medium 4.3Before 5.9.9.8Fixed in 5.9.9.82 Aug 2026
Privilege escalation
CVE-2026-12687
High 7.5Before 5.9.9.8Fixed in 5.9.9.830 Jul 2026
Broken access control
CVE-2026-12688
Medium 6.5Before 5.9.9.7Fixed in 5.9.9.724 Jul 2026
Broken access control
CVE-2026-12689
Medium 5.4Before 5.9.9.7Fixed in 5.9.9.724 Jul 2026
Broken access control
CVE-2026-12690
Low 3.8Before 5.9.9.7Fixed in 5.9.9.724 Jul 2026
Privilege escalation
CVE-2026-12073
Critical 9.8Up to 5.9.9.5Fixed in a later version (latest 6.0.0.3)30 Jun 2026
Cross-site scripting (XSS)
CVE-2026-4610
Medium 6.4Up to 5.9.9.2Fixed in a later version (latest 6.0.0.3)23 Jun 2026
Broken access control
CVE-2026-4607
Medium 4.3Up to 5.9.8.4Fixed in a later version (latest 6.0.0.3)13 May 2026
SQL injection
CVE-2026-4608
Medium 6.5Up to 5.9.8.4Fixed in a later version (latest 6.0.0.3)13 May 2026
Broken access control
CVE-2026-4609
High 7.1Up to 5.9.8.4Fixed in a later version (latest 6.0.0.3)13 May 2026
Broken access control
CVE-2026-2488
Medium 4.3Up to 5.9.8.1Fixed in a later version (latest 6.0.0.3)7 Mar 2026
Cross-site request forgery (CSRF)
CVE-2026-2494
Medium 4.3Up to 5.9.8.2Fixed in a later version (latest 6.0.0.3)7 Mar 2026
Broken access control
CVE-2026-1271
Medium 5.3Up to 5.9.7.2Fixed in a later version (latest 6.0.0.3)5 Feb 2026
Broken access control
CVE-2025-13416
Medium 4.3Up to 5.9.7.2Fixed in a later version (latest 6.0.0.3)5 Feb 2026
Cross-site scripting (XSS)
CVE-2025-6977
Medium 6.1Before 5.9.5.5Fixed in 5.9.5.516 Jul 2025
SQL injection
CVE-2025-0723
Medium 6.5Before 5.9.4.8Fixed in 5.9.4.822 Mar 2025
PHP object injection
CVE-2025-0724
High 8.8Before 5.9.4.6Fixed in 5.9.4.622 Mar 2025
Broken access control
CVE-2025-1408
Medium 4.3Before 5.9.4.5Fixed in 5.9.4.522 Mar 2025
Broken access control
CVE-2024-13740
Medium 4.3Before 5.9.4.3Fixed in 5.9.4.318 Feb 2025
Server-side request forgery (SSRF)
CVE-2024-13741
Medium 5.4Before 5.9.4.3Fixed in 5.9.4.318 Feb 2025
Broken access control
CVE-2024-10900
Medium 6.5Before 5.9.3.7Fixed in 5.9.3.720 Nov 2024
Cross-site scripting (XSS)
CVE-2024-8861
Medium 6.4Before 5.9.3.3Fixed in 5.9.3.326 Sep 2024
Broken access control
CVE-2024-6410
Medium 4.3Before 5.9.0Fixed in 5.9.010 Jul 2024
Privilege escalation
CVE-2024-6411
High 8.8Before 5.9.0Fixed in 5.9.010 Jul 2024
Broken access control
CVE-2024-5453
Medium 4.3Before 5.8.7Fixed in 5.8.75 Jun 2024
Broken access control
CVE-2024-3606
Medium 4.3Before 5.8.4Fixed in 5.8.42 May 2024
Broken access control
CVE-2023-3404
Medium 4.9Up to 5.5.0Fixed in a later version (latest 6.0.0.3)31 Aug 2023
Privilege escalation
CVE-2023-3713
High 8.8Up to 5.5.1Fixed in a later version (latest 6.0.0.3)18 Jul 2023
Privilege escalation
CVE-2023-3714
High 7.5Before 5.5.3Fixed in 5.5.318 Jul 2023
Broken access control
CVE-2023-3403
Medium 5.4Up to 5.5.1Fixed in a later version (latest 6.0.0.3)18 Jul 2023
Broken access control
CVE-2023-0940
High 8.8Before 5.3.1Fixed in 5.3.120 Mar 2023
CSV injection
CVE-2022-41791
Medium 6.8Up to 5.1.6Fixed in a later version (latest 6.0.0.3)17 Nov 2022
Cross-site scripting (XSS)
CVE-2022-3578
Medium 6.1Before 5.1.1Fixed in 5.1.114 Nov 2022
Cross-site scripting (XSS)
CVE-2022-0233
Medium 6.4Up to 4.7.4Fixed in a later version (latest 6.0.0.3)18 Jan 2022
Remote code execution
CVE-2019-15873
High 8.8Before 2.8.6Fixed in 2.8.63 Sep 2019
Read the published descriptions
CVE-2026-62061, 1 Oct 2026
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfileGrid: from n/a through 6.0.0.2. CVE record
CVE-2026-16290, 6 Aug 2026
The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list, and registers the handler for unauthenticated users, allowing any unauthenticated visitor to disclose the members and their identifiers of any group, including private or closed ones, bypassing the ProfileGrid WordPress plugin before 6.0.0.0's member-visibility setting. CVE record
CVE-2026-16289, 3 Aug 2026
The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user such as a Subscriber to disclose the names and request dates of the users awaiting approval to join any group, including private ones. CVE record
CVE-2026-16291, 2 Aug 2026
The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user before deleting it, allowing any authenticated user such as a Subscriber to delete other users' notifications by enumerating notification identifiers. CVE record
CVE-2026-12687, 30 Jul 2026
The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into through its front-end registration, allowing unauthenticated users to register directly into a privileged group and be granted that group's configured role, up to Administrator when such a group exists, leading to privilege escalation. CVE record
CVE-2026-12688, 24 Jul 2026
The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group membership, allowing unauthenticated attackers to forge a payment notification and mark any user as a paid member of any group without any payment being made. CVE record
CVE-2026-12689, 24 Jul 2026
The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions, allowing authenticated users with Subscriber-level access and above to soft-delete, tamper with the metadata of, and mark as read other users' private message threads. CVE record
CVE-2026-12690, 24 Jul 2026
The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its license management actions, relying only on a nonce that is exposed to any logged-in user, allowing authenticated users with Subscriber-level access and above to overwrite the site's premium license settings. CVE record
CVE-2026-12073, 30 Jun 2026
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.9.9.5. This is due to the plugin not validating a `user_login` on registration forms that don't contain this parameter, and not properly handling the error messages. This makes it possible for unauthenticated attackers to change email address of user account with ID=1 (usually an administrator), and leverage that to reset the user's password and gain access to their account. CVE record
CVE-2026-4610, 23 Jun 2026
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pm_author_message' parameter in the pm_send_message_to_author function in all versions up to, and including, 5.9.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 5.9.8.5. CVE record
CVE-2026-4607, 13 May 2026
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.9.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action via the pm_set_group_order, pm_set_group_items, and pm_set_field_order AJAX actions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify site-wide ProfileGrid group settings including group menu order, group list order, group icon display, and field ordering. CVE record
CVE-2026-4608, 13 May 2026
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind SQL Injection via the 'rid' parameter in all versions up to, and including, 5.9.8.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2026-4609, 13 May 2026
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the pm_invite_user function in all versions up to, and including, 5.9.8.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to add themselves or any registered user to any ProfileGrid group, including closed and paid groups, bypassing all authorization and payment gates. CVE record
CVE-2026-2488, 7 Mar 2026
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized message deletion due to a missing capability check on the pg_delete_msg() function in all versions up to, and including, 5.9.8.1. This is due to the function not verifying that the requesting user has permission to delete the targeted message. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary messages belonging to any user by sending a direct request with a valid message ID (mid parameter). CVE record
CVE-2026-2494, 7 Mar 2026
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.9.8.2. This is due to missing nonce validation on the membership request management page (approve and decline actions). This makes it possible for unauthenticated attackers to approve or deny group membership requests via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. CVE record
CVE-2026-1271, 5 Feb 2026
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.7.2 via the 'pm_upload_image' and 'pm_upload_cover_image' AJAX actions. This is due to the update_user_meta() function being called outside of the user authorization check in public/partials/crop.php and public/partials/coverimg_crop.php. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change any user's profile picture or cover image, including administrators. CVE record
CVE-2025-13416, 5 Feb 2026
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized user suspension due to a missing capability check on the pm_deactivate_user_from_group() function in all versions up to, and including, 5.9.7.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to suspend arbitrary users from groups, including administrators, via the pm_deactivate_user_from_group AJAX action. CVE record
CVE-2025-6977, 16 Jul 2025
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘pm_get_messenger_notification’ function in all versions up to, and including, 5.9.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a logged-in user into performing an action such as clicking on a link. CVE record
CVE-2025-0723, 22 Mar 2025
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind and time-based SQL Injections via the rid and search parameters in all versions up to, and including, 5.9.4.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2025-0724, 22 Mar 2025
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.9.4.5 via deserialization of untrusted input in the get_user_meta_fields_html function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present. CVE record
CVE-2025-1408, 22 Mar 2025
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_decline_join_group_request and pm_approve_join_group_request functions in all versions up to, and including, 5.9.4.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to approve or decline join group requests which is normally should be available to administrators only. CVE record
CVE-2024-13740, 18 Feb 2025
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.4.2 via the pm_messenger_show_messages function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read private conversations of other users. CVE record
CVE-2024-13741, 18 Feb 2025
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 5.9.4.2 via the pm_upload_image function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to download and view images, as well as validating if a non-image file exists, both on local or remote hosts. CVE record
CVE-2024-10900, 20 Nov 2024
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_remove_file_attachment() function in all versions up to, and including, 5.9.3.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary user meta which can do things like deny an administrator's access to their site. . CVE record
CVE-2024-8861, 26 Sep 2024
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.9.3.2 due to incorrect use of the wp_kses_allowed_html function, which allows the 'onclick' attribute for certain HTML elements without sufficient restriction or context validation. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-6410, 10 Jul 2024
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.8.9 via the 'pm_upload_image' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the profile picture of any user. CVE record
CVE-2024-6411, 10 Jul 2024
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.8.9. This is due to a lack of validation on user-supplied data in the 'pm_upload_image' AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update their user capabilities to Administrator. CVE record
CVE-2024-5453, 5 Jun 2024
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_dismissible_notice and pm_wizard_update_group_icon functions in all versions up to, and including, 5.8.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary options to the value '1' or change group icons. CVE record
CVE-2024-3606, 2 May 2024
The ProfileGrid - User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the pm_upload_cover_image function in all versions up to, and including, 5.8.3. This makes it possible for authenticated attackers, with subscriber access or higher, to delete attachments. CVE record
CVE-2023-3404, 31 Aug 2023
The ProfileGrid plugin for WordPress is vulnerable to unauthorized decryption of private information in versions up to, and including, 5.5.0. This is due to the passphrase and iv being hardcoded in the 'pm_encrypt_decrypt_pass' function and used across all sites running the plugin. This makes it possible for authenticated attackers, with administrator-level permissions or above to decrypt and view users' passwords. If combined with another vulnerability, this can potentially grant lower-privileged users access to users' passwords. CVE record
CVE-2023-3713, 18 Jul 2023
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'profile_magic_check_smtp_connection' function in versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update the site options arbitrarily. This can be used by attackers to achieve privilege escalation. CVE record
CVE-2023-3714, 18 Jul 2023
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'edit_group' handler in versions up to, and including, 5.5.2. This makes it possible for authenticated attackers, with group ownership, to update group options, including the 'associate_role' parameter, which defines the member's role. This issue was partially patched in version 5.5.2 preventing privilege escalation, however, it was fully patched in 5.5.3. CVE record
CVE-2023-3403, 18 Jul 2023
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pm_upload_csv' function in versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with subscriber-level permissions or above to import new users and update existing users. CVE record
CVE-2023-0940, 20 Mar 2023
The ProfileGrid WordPress plugin before 5.3.1 provides an AJAX endpoint for resetting a user password but does not implement proper authorization. This allows a user with low privileges, such as subscriber, to change the password of any account, including Administrator ones. CVE record
CVE-2022-41791, 17 Nov 2022
Auth. (subscriber+) CSV Injection vulnerability in ProfileGrid plugin <= 5.1.6 on WordPress. CVE record
CVE-2022-3578, 14 Nov 2022
The ProfileGrid WordPress plugin before 5.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting CVE record
CVE-2022-0233, 18 Jan 2022
The ProfileGrid - User Profiles, Memberships, Groups and Communities WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the pm_user_avatar and pm_cover_image parameters found in the ~/admin/class-profile-magic-admin.php file which allows attackers with authenticated user access, such as subscribers, to inject arbitrary web scripts into their profile, in versions up to and including 1.2.7. CVE record
CVE-2019-15873, 3 Sep 2019
The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an wp-admin/admin-ajax.php request with the action=pm_template_preview&html=<?php substring followed by PHP code. CVE record

What to do if you run ProfileGrid

If you run ProfileGrid, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new ProfileGrid vulnerabilities

Free. We email you when a new vulnerability is published for ProfileGrid, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support