Access violation vulnerability in ProfileGrid – User Profiles, Groups and Communities 5.9.4.4

The ProfileGrid plugin for WordPress can be changed without permission, which could allow someone to access and change information without the proper authorization. This can happen in all versions up to 5.9.4.4. It means that someone who is logged in and has access as a Subscriber or higher could approve or decline requests to join a group, which is usually a task for administrators only.

Detected in:

ProfileGrid – User Profiles, Memberships, Groups and Communities fixed vulnerable versions: >= * <= 5.9.4.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.