Vulnerabilities > Metagauss > Profilegrid > 5.9.4.6

DATE CVE VULNERABILITY TITLE RISK
2025-03-22 CVE-2025-0723 SQL Injection vulnerability in Metagauss Profilegrid
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind and time-based SQL Injections via the rid and search parameters in all versions up to, and including, 5.9.4.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
metagauss CWE-89
6.5