WordPress security by component
ProfileGrid
Plugin description
ProfileGrid is a WordPress component with 55 published CVE records in this archive. The latest tracked vulnerability was published Jul 24, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
profilegrid-user-profiles-groups-and-communitiesLatest vulnerability
CVE-2026-12690: ProfileGrid lets Subscribers overwrite premium license settings
ProfileGrid before 5.9.9.7 exposes the pg_activate_license and pg_deactivate_license AJAX actions without a capability check. Their nonce is localized into wp-admin for any logged-in user, so a Subscriber can submit attacker-controlled pg_license, pg_item_id and pg_item_key values and overwrite or create the plugin's namespaced license options.
| Safe version |
|
||
|---|---|---|---|
| Jul 24, 2026 |
CVE-2026-12690
ProfileGrid lets Subscribers overwrite premium license settings
ProfileGrid before 5.9.9.7 exposes the pg_activate_license and pg_deactivate_license AJAX actions without a capability check. Their nonce is localized into wp-admin for any logged-in user, so a Subscriber can submit attacker-controlled pg_license, pg_item_id and pg_item_key values and overwrite or create the plugin's namespaced license options.
|
5.9.9.7 |
CVE4.3
NVDPending
|
| Jul 24, 2026 |
CVE-2026-12689
ProfileGrid private-message actions permit cross-user tampering
ProfileGrid before 5.9.9.7 allows any authenticated user, including a Subscriber, to call the pm_messenger_delete_threads and pm_messages_mark_as_read AJAX actions for another user's numeric thread ID. The handlers do not verify thread participation or ownership, allowing a nonparticipant to soft-delete a victim thread, write attacker-selected deletion metadata and mark its messages as read.
|
5.9.9.7 |
CVE5.4
NVDPending
|
| Jul 24, 2026 |
CVE-2026-12688
ProfileGrid accepts forged PayPal membership notifications
ProfileGrid before 5.9.9.7 processes an unauthenticated action=ipn request on a published group page without validating it with PayPal. Attacker-controlled payment_status and custom values reach the membership handler, allowing any selected user ID to be marked as a paid member of any selected group even when the amount, receiver and transaction were not legitimate.
|
5.9.9.7 |
CVE5.3
NVDPending
|
| Jul 13, 2026 |
CVE-2026-57697
ProfileGrid: Privilege escalation or authentication bypass
ProfileGrid is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 5.9.9.6.
|
5.9.9.7 |
CVE7.5
NVDPending
|
| Jul 02, 2026 |
CVE-2026-57759
ProfileGrid: Cross-site request forgery
ProfileGrid is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is n/a through 5.9.9.7.
|
> 5.9.9.7 |
CVE8.8
NVDPending
|
| Jun 30, 2026 |
CVE-2026-12073
ProfileGrid – User Profiles, Groups and Communities: Privilege escalation or authentication bypass
ProfileGrid – User Profiles, Groups and Communities is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 5.9.9.5.
|
> 5.9.9.5 |
CVE9.8
NVDPending
|
| Jun 23, 2026 |
CVE-2026-4610
ProfileGrid – User Profiles, Groups and Communities: Cross-site scripting
ProfileGrid – User Profiles, Groups and Communities is affected by cross-site scripting. Exploitation requires at least subscriber-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 5.9.9.2.
|
> 5.9.9.2 |
CVE6.4
NVDPending
|
| May 13, 2026 |
CVE-2026-4609
ProfileGrid – User Profiles, Groups and Communities: A security weakness
ProfileGrid – User Profiles, Groups and Communities is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 5.9.8.4.
|
> 5.9.8.4 |
CVE7.1
NVDPending
|
| May 13, 2026 |
CVE-2026-4608
ProfileGrid – User Profiles, Groups and Communities: SQL injection
ProfileGrid – User Profiles, Groups and Communities is affected by SQL injection. Exploitation requires at least subscriber-level access. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 5.9.8.4.
|
> 5.9.8.4 |
CVE6.5
NVDPending
|
| May 13, 2026 |
CVE-2026-4607
ProfileGrid – User Profiles, Groups and Communities: A security weakness
ProfileGrid – User Profiles, Groups and Communities is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 5.9.8.4.
|
> 5.9.8.4 |
CVE4.3
NVDPending
|
| Mar 25, 2026 |
CVE-2026-25417
ProfileGrid: Cross-site scripting
ProfileGrid is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 5.9.8.1.
|
5.9.8.2 |
CVE6.5
NVDPending
|
| Mar 07, 2026 |
CVE-2026-2494
ProfileGrid – User Profiles, Groups and Communities: Cross-site request forgery
ProfileGrid – User Profiles, Groups and Communities is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Mar 07, 2026 |
CVE-2026-2488
ProfileGrid – User Profiles, Groups and Communities: A security weakness
ProfileGrid – User Profiles, Groups and Communities is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Feb 05, 2026 |
CVE-2026-1271
ProfileGrid – User Profiles, Groups and Communities: A security weakness
ProfileGrid – User Profiles, Groups and Communities is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Feb 05, 2026 |
CVE-2025-13416
ProfileGrid – User Profiles, Groups and Communities: A security weakness
ProfileGrid – User Profiles, Groups and Communities is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Sep 26, 2025 |
CVE-2025-4957
ProfileGrid: Cross-site scripting
ProfileGrid is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVDPending
|
| Aug 14, 2025 |
CVE-2025-49033
ProfileGrid: SQL injection
ProfileGrid is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.5
NVDPending
|
| Jul 16, 2025 |
CVE-2025-49876
ProfileGrid: SQL injection
ProfileGrid is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.5
NVDPending
|
| Jul 16, 2025 |
CVE-2025-6977
ProfileGrid – User Profiles, Groups and Communities: Cross-site scripting
ProfileGrid – User Profiles, Groups and Communities is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVDPending
|
| Jun 20, 2025 |
CVE-2025-52719
ProfileGrid: A security weakness
ProfileGrid is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jun 17, 2025 |
CVE-2025-49877
ProfileGrid: Server-side request forgery
ProfileGrid is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVE4.9
NVDPending
|
| May 23, 2025 |
CVE-2025-47478
ProfileGrid: SQL injection
ProfileGrid is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.5
NVDPending
|
| May 16, 2025 |
CVE-2025-48079
ProfileGrid: A security weakness
ProfileGrid is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Apr 17, 2025 |
CVE-2025-39586
ProfileGrid: SQL injection
ProfileGrid is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.5
NVDPending
|
| Mar 22, 2025 |
CVE-2025-1408
ProfileGrid – User Profiles, Groups and Communities: A security weakness
ProfileGrid – User Profiles, Groups and Communities is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Mar 22, 2025 |
CVE-2025-0724
ProfileGrid – User Profiles, Groups and Communities: Code execution
ProfileGrid – User Profiles, Groups and Communities is affected by code execution. Exploitation requires at least subscriber-level access. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Mar 22, 2025 |
CVE-2025-0723
ProfileGrid – User Profiles, Groups and Communities: SQL injection
ProfileGrid – User Profiles, Groups and Communities is affected by SQL injection. Exploitation requires at least subscriber-level access. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Mar 03, 2025 |
CVE-2025-26999
ProfileGrid: Code execution
ProfileGrid is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Feb 18, 2025 |
CVE-2024-13740
ProfileGrid – User Profiles, Groups and Communities: A security weakness
ProfileGrid – User Profiles, Groups and Communities is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Feb 18, 2025 |
CVE-2024-13741
ProfileGrid – User Profiles, Groups and Communities: Server-side request forgery
ProfileGrid – User Profiles, Groups and Communities is affected by server-side request forgery. Exploitation requires at least subscriber-level access. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Nov 20, 2024 |
CVE-2024-10900
ProfileGrid – User Profiles, Groups and Communities: A security weakness
ProfileGrid – User Profiles, Groups and Communities is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD8.1
|
| Nov 01, 2024 |
CVE-2024-37453
ProfileGrid: A security weakness
ProfileGrid is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Sep 26, 2024 |
CVE-2024-8861
ProfileGrid – User Profiles, Groups and Communities: Cross-site scripting
ProfileGrid – User Profiles, Groups and Communities is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jul 10, 2024 |
CVE-2024-6411
ProfileGrid – User Profiles, Groups and Communities: Privilege escalation or authentication bypass
ProfileGrid – User Profiles, Groups and Communities is affected by privilege escalation or authentication bypass. Exploitation requires at least subscriber-level access. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Jul 10, 2024 |
CVE-2024-6410
ProfileGrid – User Profiles, Groups and Communities: A security weakness
ProfileGrid – User Profiles, Groups and Communities is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jun 12, 2024 |
CVE-2023-52117
ProfileGrid: A security weakness
ProfileGrid is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD6.3
|
| Jun 05, 2024 |
CVE-2024-5453
ProfileGrid – User Profiles, Groups and Communities: A security weakness
ProfileGrid – User Profiles, Groups and Communities is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| May 17, 2024 |
CVE-2024-32774
ProfileGrid: A security weakness
ProfileGrid is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Apr 24, 2024 |
CVE-2024-32808
ProfileGrid: A security weakness
ProfileGrid is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVD8.8
|
| Apr 24, 2024 |
CVE-2024-32772
ProfileGrid: A security weakness
ProfileGrid is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Apr 12, 2024 |
CVE-2024-31362
ProfileGrid: Cross-site request forgery
ProfileGrid is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Apr 07, 2024 |
CVE-2024-31291
ProfileGrid: A security weakness
ProfileGrid is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD7.1
|
| Mar 29, 2024 |
CVE-2024-30513
ProfileGrid: A security weakness
ProfileGrid is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Mar 29, 2024 |
CVE-2024-30491
ProfileGrid: SQL injection
ProfileGrid is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.5
NVD8.8
|
| Mar 29, 2024 |
CVE-2024-30490
ProfileGrid: SQL injection
ProfileGrid is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.3
NVD9.8
|
| Mar 28, 2024 |
CVE-2024-30241
ProfileGrid: SQL injection
ProfileGrid is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.5
NVD8.8
|
| Jan 08, 2024 |
CVE-2022-36352
ProfileGrid – User Profiles, Memberships, Groups and Communities: A security weakness
ProfileGrid – User Profiles, Memberships, Groups and Communities is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.3
NVD8.8
|
| Nov 18, 2023 |
CVE-2023-47644
ProfileGrid – User Profiles, Memberships, Groups and Communities: Cross-site request forgery
ProfileGrid – User Profiles, Memberships, Groups and Communities is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD8.8
|
| Aug 31, 2023 |
CVE-2023-3404
ProfileGrid: A security weakness
ProfileGrid is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.9
NVDPending
|
| Jul 18, 2023 |
CVE-2023-3714
ProfileGrid: Privilege escalation or authentication bypass
ProfileGrid is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated WordPress account. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE7.5
NVD8.8
|
| Jul 18, 2023 |
CVE-2023-3713
ProfileGrid: Privilege escalation or authentication bypass
ProfileGrid is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated WordPress account. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Jul 18, 2023 |
CVE-2023-3403
ProfileGrid: A security weakness
ProfileGrid is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVD4.3
|
| Nov 17, 2022 |
CVE-2022-41791
Profilegrid User Profiles Groups And Communities: A security weakness
Profilegrid User Profiles Groups And Communities is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.8
NVD8.8
|
| Jan 18, 2022 |
CVE-2022-0233
ProfileGrid – User Profiles, Memberships, Groups and Communities: Cross-site scripting
ProfileGrid – User Profiles, Memberships, Groups and Communities is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Sep 03, 2019 |
CVE-2019-15873
Profilegrid User Profiles Groups And Communities: Code execution
Profilegrid User Profiles Groups And Communities is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE8.8
NVD8.8
|