Input validation vulnerability in ProfileGrid – User Profiles, Groups and Communities 5.9.4.3

The ProfileGrid plugin for WordPress has a security issue where untrusted information can be used to inject a type of code called PHP Object. This vulnerability exists in versions up to 5.9.4.3 and can be exploited by attackers who have at least subscriber-level access. If there is another plugin or theme installed on the website, the attacker may be able to delete files, access sensitive information, or run their own code.

Detected in:

ProfileGrid – User Profiles, Memberships, Groups and Communities fixed vulnerable versions: >= * <= 5.9.4.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.