Vulnerabilities > Metagauss > Profilegrid > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-10-21 CVE-2024-49273 Missing Authorization vulnerability in Metagauss Profilegrid
Missing Authorization vulnerability in ProfileGrid User Profiles ProfileGrid.This issue affects ProfileGrid: from n/a through 5.9.3.
network
low complexity
metagauss CWE-862
6.5
2024-09-26 CVE-2024-8861 Cross-site Scripting vulnerability in Metagauss Profilegrid
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.9.3.2 due to incorrect use of the wp_kses_allowed_html function, which allows the 'onclick' attribute for certain HTML elements without sufficient restriction or context validation.
network
low complexity
metagauss CWE-79
5.4
2024-06-12 CVE-2023-52117 Missing Authorization vulnerability in Metagauss Profilegrid
Missing Authorization vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid: from n/a through 5.6.6.
network
low complexity
metagauss CWE-862
6.3
2024-06-05 CVE-2024-5453 Missing Authorization vulnerability in Metagauss Profilegrid
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_dismissible_notice and pm_wizard_update_group_icon functions in all versions up to, and including, 5.8.6.
network
low complexity
metagauss CWE-862
4.3
2023-08-31 CVE-2023-3404 Unspecified vulnerability in Metagauss Profilegrid
The ProfileGrid plugin for WordPress is vulnerable to unauthorized decryption of private information in versions up to, and including, 5.5.0.
network
low complexity
metagauss
4.9
2023-07-18 CVE-2023-3403 Unspecified vulnerability in Metagauss Profilegrid
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pm_upload_csv' function in versions up to, and including, 5.5.1.
network
low complexity
metagauss
4.3
2022-11-14 CVE-2022-3578 Cross-site Scripting vulnerability in Metagauss Profilegrid
The ProfileGrid WordPress plugin before 5.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
network
low complexity
metagauss CWE-79
6.1
2019-09-03 CVE-2019-15873 Code Injection vulnerability in Metagauss Profilegrid
The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an wp-admin/admin-ajax.php request with the action=pm_template_preview&html=<?php substring followed by PHP code.
network
low complexity
metagauss CWE-94
6.5