Potential Privilege Escalation Vulnerability in ProfileGrid User Profiles, Groups and Communities Plugin
CVE-2024-6411
8.8HIGH
What is CVE-2024-6411?
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress has a vulnerability associated with privilege escalation that impacts all versions up to and including 5.8.9. This flaw arises from a lack of proper validation on user-supplied data within the 'pm_upload_image' AJAX action. Consequently, authenticated attackers with Subscriber-level access or higher may exploit this weakness to elevate their user capabilities to that of an Administrator, compromising the integrity and security of WordPress installations utilizing this plugin.