ProfileGrid – User Profiles, Memberships, Groups and Communities

ProfileGrid is a user profile, member and directory plugin that offers user groups, multiple profile types, custom fields, group managers, registration workflows, membership limits, and more. It brings together user data from all plugins that use custom posts or shortcodes, and is the #1 free WooCommerce and bbPress user profile plugin. Contact their support team for any issues, bugs, feature requests, or general help.

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Input validation vulnerability in ProfileGrid – User Profiles, Groups and Communities 5.9.5.7

    Fixed

    The ProfileGrid plugin for WordPress, which allows users to create profiles, groups, and communities, has a security issue called Reflected Cross-Site Scripting. This means that attackers can inject ...

    Read More
  • Input validation vulnerability in ProfileGrid – User Profiles, Groups and Communities 5.9.5.3

    Fixed

    The ProfileGrid plugin for WordPress has a security issue in versions 5.9.5.3 and below. This is because the plugin does not properly protect against SQL Injection, a type of attack that can allow ha...

    Read More
  • Input validation vulnerability in ProfileGrid – User Profiles, Groups and Communities 5.9.5.2

    Fixed

    A popular tool for WordPress, called ProfileGrid, has a security issue that could allow hackers to access sensitive information. This is because the plugin does not properly handle certain types of d...

    Read More
  • Input validation vulnerability in ProfileGrid – User Profiles, Groups and Communities 5.9.5.4

    Fixed

    The ProfileGrid plugin for WordPress has a security issue that allows attackers to inject harmful code onto a website. This can happen if they can trick a logged-in user into clicking a link. The vul...

    Read More
  • Access violation vulnerability in ProfileGrid – User Profiles, Groups and Communities 5.9.5.2

    Fixed

    The ProfileGrid plugin for WordPress has a security issue where the full path of the website can be accessed by unauthorized users. This information is not harmful on its own, but can assist with oth...

    Read More
  • Input validation vulnerability in ProfileGrid – User Profiles, Groups and Communities 5.9.5.2

    Fixed

    The ProfileGrid plugin, used for user profiles, groups, and communities on WordPress, has a security issue called Server-Side Request Forgery. This means that anyone with at least Subscriber-level ac...

    Read More
  • Access violation vulnerability in ProfileGrid – User Profiles, Groups and Communities 5.9.5.1

    Fixed

    The ProfileGrid plugin for WordPress has a security issue that allows unauthorized users to access it without proper permission checks. This vulnerability affects all versions up to and including 5.9...

    Read More
  • Input validation vulnerability in ProfileGrid – User Profiles, Groups and Communities 5.9.5.0

    Fixed

    The ProfileGrid plugin for WordPress has a security issue that could allow attackers to access sensitive information from the website's database. This vulnerability affects versions up to and includi...

    Read More
  • Input validation vulnerability in ProfileGrid – User Profiles, Groups and Communities 5.9.4.8

    Fixed

    The ProfileGrid plugin for WordPress has a security issue that allows hackers to access sensitive information from the database. This can happen because the plugin does not properly handle user-provi...

    Read More
  • Access violation vulnerability in ProfileGrid – User Profiles, Groups and Communities 5.9.4.4

    Fixed

    The ProfileGrid plugin for WordPress can be changed without permission, which could allow someone to access and change information without the proper authorization. This can happen in all versions up...

    Read More
  • Input validation vulnerability in ProfileGrid – User Profiles, Groups and Communities 5.9.4.7

    Fixed

    The ProfileGrid plugin for WordPress has a security vulnerability that allows attackers to inject malicious code through the rid and search parameters. This can happen in all versions up to 5.9.4.7 b...

    Read More
  • Input validation vulnerability in ProfileGrid – User Profiles, Groups and Communities 5.9.4.5

    Fixed

    The ProfileGrid plugin for WordPress has a security vulnerability that allows attackers with certain levels of access to inject malicious code. This can only happen if another plugin or theme with a ...

    Read More
  • Input validation vulnerability in ProfileGrid – User Profiles, Groups and Communities 5.9.4.3

    Fixed

    The ProfileGrid plugin for WordPress has a security issue where untrusted information can be used to inject a type of code called PHP Object. This vulnerability exists in versions up to 5.9.4.3 and c...

    Read More
  • Access violation vulnerability in ProfileGrid – User Profiles, Groups and Communities 5.9.4.2

    Fixed

    The ProfileGrid plugin for WordPress has a security issue called Insecure Direct Object Reference. This allows attackers with Subscriber-level access or higher to view private conversations of other ...

    Read More
  • Input validation vulnerability in ProfileGrid – User Profiles, Groups and Communities 5.9.4.2

    Fixed

    A popular plugin for WordPress called ProfileGrid has a security issue called Limited Server-Side Request Forgery. This means that attackers who have access to the website can make requests to other ...

    Read More
  • Access violation vulnerability in ProfileGrid – User Profiles, Groups and Communities 5.9.3.6

    Fixed

    A WordPress plugin called ProfileGrid, which allows users to create profiles, groups, and communities, has a security vulnerability. This means that unauthorized people may be able to change data wit...

    Read More
  • Input validation vulnerability in ProfileGrid – User Profiles, Groups and Communities 5.9.3

    Fixed

    A security issue has been identified in the ProfileGrid plugin for WordPress versions up to and including 5.9.3. This vulnerability is caused by a lack of proper security checks, which allows attacke...

    Read More
  • Input validation vulnerability in ProfileGrid – User Profiles, Groups and Communities 5.9.3.2

    Fixed

    A plugin called ProfileGrid, used for creating user profiles, groups, and communities on WordPress, has a security issue. This issue, known as Stored Cross-Site Scripting, affects all versions of the...

    Read More
  • Access violation vulnerability in ProfileGrid – User Profiles, Groups and Communities 5.8.9

    Fixed

    The ProfileGrid plugin for WordPress is at risk of a security issue called Insecure Direct Object Reference. This affects all versions up to 5.8.9 and is caused by a function called 'pm_upload_image'...

    Read More
  • Access violation vulnerability in ProfileGrid – User Profiles, Groups and Communities 5.8.9

    Fixed

    The ProfileGrid plugin used for WordPress has a security issue that affects all versions up to and including 5.8.9. This problem happens because the plugin doesn't properly check the data that users ...

    Read More
  • Access violation vulnerability in ProfileGrid – User Profiles, Groups and Communities 5.8.7

    Fixed

    The ProfileGrid plugin for WordPress has a security issue that allows unauthorized users to access it. This is because the plugin does not check for proper permissions before allowing the "pm_create_...

    Read More
  • Access violation vulnerability in ProfileGrid – User Profiles, Groups and Communities 5.8.6

    Fixed

    The ProfileGrid plugin for WordPress has a security flaw that allows unauthorized changes to be made to the data. This is because some functions in the plugin do not have proper checks in place. This...

    Read More
  • Input validation vulnerability in ProfileGrid – User Profiles, Memberships, Groups and Communities 5.7.1

    Fixed

    The ProfileGrid plugin for WordPress has a security vulnerability that allows attackers with contributor-level access or higher to access sensitive information from the database. This is because the ...

    Read More
  • Access violation vulnerability in ProfileGrid 5.7.9

    Fixed

    The ProfileGrid plugin for WordPress has a security vulnerability that affects all versions up to 5.7.9. This vulnerability, known as Insecure Direct Object Reference, occurs because the plugin does ...

    Read More
  • Access violation vulnerability in ProfileGrid – User Profiles, Memberships, Groups and Communities 5.8.2

    Fixed

    The ProfileGrid plugin for WordPress has a vulnerability that allows attackers to bypass group limits. This means that anyone with subscriber-level access or higher can add more members to a group th...

    Read More
  • Access violation vulnerability in ProfileGrid – User Profiles, Memberships, Groups and Communities 5.7.9

    Fixed

    The ProfileGrid plugin for WordPress has a security vulnerability that allows unauthorized users to view other people's messages. This vulnerability exists in all versions up to and including 5.7.9. ...

    Read More
  • Access violation vulnerability in ProfileGrid – User Profiles, Memberships, Groups and Communities 5.8.3

    Fixed

    The ProfileGrid plugin for WordPress has a security issue that could allow people to delete data without permission. This problem affects all versions up to and including 5.8.3. This means that someo...

    Read More
  • Input validation vulnerability in ProfileGrid – User Profiles, Memberships, Groups and Communities 5.7.8

    Fixed

    The ProfileGrid plugin for WordPress has a security issue that allows unauthorized users to delete groups. This is because the plugin does not properly check if the request is legitimate. Attackers c...

    Read More
  • Access violation vulnerability in ProfileGrid – User Profiles, Memberships, Groups and Communities 5.7.6

    Fixed

    The ProfileGrid plugin for WordPress is not secure in versions up to 5.7.6. This is because it does not properly check a key that is controlled by the user. This means that someone who is logged in a...

    Read More
  • Access violation vulnerability in ProfileGrid – User Profiles, Memberships, Groups and Communities 5.7.2

    Fixed

    A popular tool for WordPress called ProfileGrid has a security issue that affects all versions up to 5.7.2. This means that anyone who has a certain level of access to the website, including subscrib...

    Read More
  • Input validation vulnerability in ProfileGrid – User Profiles, Memberships, Groups and Communities 5.7.8

    Fixed

    The ProfileGrid plugin for WordPress has a security issue that could allow hackers to access sensitive information from the database. This vulnerability exists in versions up to 5.7.8 because the plu...

    Read More
  • Input validation vulnerability in ProfileGrid – User Profiles, Memberships, Groups and Communities 5.7.8

    Fixed

    The ProfileGrid plugin for WordPress has a security issue that allows hackers to access sensitive information from the database. This is because the plugin does not properly protect against SQL Injec...

    Read More
  • Access violation vulnerability in ProfileGrid – User Profiles, Memberships, Groups and Communities 5.6.6

    Fixed

    The ProfileGrid plugin for WordPress, up to version 5.6.6, contains a security vulnerability that could allow attackers with a subscriber-level account or higher to gain unauthorized access. This cou...

    Read More
  • Input validation vulnerability in ProfileGrid – User Profiles, Memberships, Groups and Communities 5.6.6

    Fixed

    The ProfileGrid WordPress plugin is vulnerable to a security issue called Cross-Site Request Forgery (CSRF). This means that if someone can trick a website administrator into clicking a link, they ca...

    Read More
  • Access violation vulnerability in ProfileGrid – User Profiles, Memberships, Groups and Communities 5.5.1

    Fixed

    The ProfileGrid plugin for WordPress is vulnerable to a problem that allows attackers to change data without permission. This problem exists on versions 5.5.1 and earlier. Attackers with a low level ...

    Read More
  • Access violation vulnerability in ProfileGrid – User Profiles, Memberships, Groups and Communities 5.5.2

    Fixed

    The ProfileGrid plugin for WordPress is a tool that can be used on websites. In versions of the plugin up to and including 5.5.2, there was a security issue that could have allowed attackers with acc...

    Read More
  • Weak configuration vulnerability in ProfileGrid – User Profiles, Memberships, Groups and Communities 5.5.0

    Fixed

    The ProfileGrid plugin for WordPress, used on websites, has a security issue in versions up to 5.5.0. Attackers who have administrator-level or above permissions can view and decrypt users' passwords...

    Read More
  • Access violation vulnerability in ProfileGrid – User Profiles, Memberships, Groups and Communities 5.5.1

    Fixed

    The ProfileGrid plugin for WordPress has a vulnerability that can allow unauthorized changes to data. This vulnerability affects all versions up to 5.5.1. If someone with a subscriber-level account o...

    Read More
  • Input validation vulnerability in ProfileGrid – User Profiles, Memberships, Groups and Communities 5.1.7

    Fixed

    The ProfileGrid plugin for WordPress is not secure in versions up to 5.1.6. An attacker with limited access can put malicious content into files that are exported as CSV files. When the CSV files are ...

    Read More
  • Input validation vulnerability in ProfileGrid – User Profiles, Memberships, Groups and Communities 2.8.6

    Fixed

    The profilegrid-user-profiles-groups-and-communities plugin for WordPress versions before 2.8.6 had a security vulnerability that allowed a malicious user to execute code remotely. This was done by se...

    Read More
  • Input validation vulnerability in ProfileGrid – User Profiles, Memberships, Groups and Communities 5.1.0

    Fixed

    The ProfileGrid plugin for WordPress

    Read More
  • Access violation vulnerability in ProfileGrid – User Profiles, Memberships, Groups and Communities 5.3.0

    Fixed

    The ProfileGrid plugin for WordPress has a security flaw that could let attackers change the passwords of any user on the site. This plugin comes with WordPress

    Read More
  • Input validation vulnerability in ProfileGrid – User Profiles, Memberships, Groups and Communities 4.7.4

    Fixed

    The ProfileGrid WordPress plugin

    Read More
  • Access violation vulnerability in ProfileGrid – User Profiles, Memberships, Groups and Communities 5.0.3

    Fixed

    The ProfileGrid plugin for WordPress is not secure in versions up to 5.0.3. It does not have enough security checks in place to stop people from accessing private messages. People who are already logg...

    Read More