Vulnerabilities > Metagauss > Profilegrid > 5.1.2

DATE CVE VULNERABILITY TITLE RISK
2023-11-18 CVE-2023-47644 Cross-Site Request Forgery (CSRF) vulnerability in Metagauss Profilegrid
Cross-Site Request Forgery (CSRF) vulnerability in profilegrid ProfileGrid – User Profiles, Memberships, Groups and Communities.This issue affects ProfileGrid – User Profiles, Memberships, Groups and Communities: from n/a through 5.6.6.
network
low complexity
metagauss CWE-352
8.8
2023-08-31 CVE-2023-3404 Unspecified vulnerability in Metagauss Profilegrid
The ProfileGrid plugin for WordPress is vulnerable to unauthorized decryption of private information in versions up to, and including, 5.5.0.
network
low complexity
metagauss
4.9
2023-07-18 CVE-2023-3403 Unspecified vulnerability in Metagauss Profilegrid
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pm_upload_csv' function in versions up to, and including, 5.5.1.
network
low complexity
metagauss
4.3
2023-07-18 CVE-2023-3713 Unspecified vulnerability in Metagauss Profilegrid
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'profile_magic_check_smtp_connection' function in versions up to, and including, 5.5.1.
network
low complexity
metagauss
8.8
2023-07-18 CVE-2023-3714 Unspecified vulnerability in Metagauss Profilegrid
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'edit_group' handler in versions up to, and including, 5.5.2.
network
low complexity
metagauss
8.8
2023-03-20 CVE-2023-0940 Incorrect Authorization vulnerability in Metagauss Profilegrid
The ProfileGrid WordPress plugin before 5.3.1 provides an AJAX endpoint for resetting a user password but does not implement proper authorization.
network
low complexity
metagauss CWE-863
8.8
2022-11-17 CVE-2022-41791 Improper Neutralization of Formula Elements in a CSV File vulnerability in Metagauss Profilegrid
Auth.
network
low complexity
metagauss CWE-1236
8.8