ProfileGrid – User Profiles, Groups and Communities <= 5.9.5.7 - Reflected Cross-Site Scripting
ProfileGrid – User Profiles, Groups and Communities
Minimum safe version
5.9.8.3
Update to 5.9.8.3 or later to address 53 fixable vulnerabilities
ProfileGrid <= 5.9.7.2 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Profile and Cover Image Modification
ProfileGrid <= 5.9.8.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Message Deletion
ProfileGrid <= 5.9.8.2 - Cross-Site Request Forgery to Group Membership Request Approval/Denial
CVE-2026-25417
CVE-2025-13416
CVE-2025-49033
ProfileGrid – User Profiles, Groups and Communities <= 5.9.5.4 - Reflected Cross-Site Scripting via 'pm_get_messenger_notification' function
CVE-2025-49876
CVE-2025-52719
CVE-2025-49877
CVE-2025-47478
CVE-2025-48079
CVE-2025-39586
ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.5 - Authenticated (Subscriber+) PHP Object Injection
ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.4 - Missing Authorinzation to Authenticated (Subscriber+) Join Group Requests Management
ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.7 - Authenticated (Subscriber+) SQL Injection
CVE-2025-26999
CVE-2024-13741
CVE-2024-13740
CVE-2024-10900
CVE-2024-49273
CVE-2024-8861
CVE-2024-6410
CVE-2024-6411
CVE-2024-37453
CVE-2024-5453
CVE-2024-32774
CVE-2024-32772
CVE-2024-32808
CVE-2024-3606
CVE-2024-31362
CVE-2024-31291
CVE-2024-30491
CVE-2024-30490
CVE-2024-30513
ProfileGrid <= 5.7.1 - Authenticated (Contributor+) SQL Injection
WordPress ProfileGrid Plugin <= 5.6.6 is vulnerable to Broken Access Control
CVE-2023-47644
ProfileGrid < 5.0.4 - Subscriber+ Private Message Read/Edition
CVE-2023-3713
CVE-2023-3714
CVE-2023-3403
CVE-2023-3404
CVE-2022-36352
CVE-2023-0940
ProfileGrid – User Profiles, Memberships, Groups and Communities <= 5.0.3 - Missing Authorization to Information Exposure
CVE-2022-41791
WordPress ProfileGrid plugin <= 5.1.0 - Reflected Cross-Site Scripting (XSS) vulnerability
WordPress ProfileGrid Plugin <= 2.6.6 - Reflected Cross Site Scripting
WordPress ProfileGrid – User Profiles, Groups and Communities plugin <= 2.8.5 - Authenticated Code Execution vulnerability
CVE-2019-15873
CVE-2022-0233