Vulnerabilities > Metagauss > Profilegrid

DATE CVE VULNERABILITY TITLE RISK
2024-10-21 CVE-2024-49273 Missing Authorization vulnerability in Metagauss Profilegrid
Missing Authorization vulnerability in ProfileGrid User Profiles ProfileGrid.This issue affects ProfileGrid: from n/a through 5.9.3.
network
low complexity
metagauss CWE-862
6.5
2024-09-26 CVE-2024-8861 Cross-site Scripting vulnerability in Metagauss Profilegrid
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.9.3.2 due to incorrect use of the wp_kses_allowed_html function, which allows the 'onclick' attribute for certain HTML elements without sufficient restriction or context validation.
network
low complexity
metagauss CWE-79
5.4
2024-06-12 CVE-2023-52117 Missing Authorization vulnerability in Metagauss Profilegrid
Missing Authorization vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid: from n/a through 5.6.6.
network
low complexity
metagauss CWE-862
6.3
2024-06-05 CVE-2024-5453 Missing Authorization vulnerability in Metagauss Profilegrid
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_dismissible_notice and pm_wizard_update_group_icon functions in all versions up to, and including, 5.8.6.
network
low complexity
metagauss CWE-862
4.3
2024-01-08 CVE-2022-36352 Missing Authorization vulnerability in Metagauss Profilegrid
Missing Authorization vulnerability in Profilegrid ProfileGrid – User Profiles, Memberships, Groups and Communities.This issue affects ProfileGrid – User Profiles, Memberships, Groups and Communities: from n/a through 5.0.3.
network
low complexity
metagauss CWE-862
8.8
2023-11-18 CVE-2023-47644 Cross-Site Request Forgery (CSRF) vulnerability in Metagauss Profilegrid
Cross-Site Request Forgery (CSRF) vulnerability in profilegrid ProfileGrid – User Profiles, Memberships, Groups and Communities.This issue affects ProfileGrid – User Profiles, Memberships, Groups and Communities: from n/a through 5.6.6.
network
low complexity
metagauss CWE-352
8.8
2023-08-31 CVE-2023-3404 Unspecified vulnerability in Metagauss Profilegrid
The ProfileGrid plugin for WordPress is vulnerable to unauthorized decryption of private information in versions up to, and including, 5.5.0.
network
low complexity
metagauss
4.9
2023-07-18 CVE-2023-3403 Unspecified vulnerability in Metagauss Profilegrid
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pm_upload_csv' function in versions up to, and including, 5.5.1.
network
low complexity
metagauss
4.3
2023-07-18 CVE-2023-3713 Unspecified vulnerability in Metagauss Profilegrid
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'profile_magic_check_smtp_connection' function in versions up to, and including, 5.5.1.
network
low complexity
metagauss
8.8
2023-07-18 CVE-2023-3714 Unspecified vulnerability in Metagauss Profilegrid
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'edit_group' handler in versions up to, and including, 5.5.2.
network
low complexity
metagauss
8.8