PHP Object Injection Vulnerability in ProfileGrid Plugin for WordPress
CVE-2025-0724
8.8HIGH
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 22 March 2025
Summary
The ProfileGrid plugin for WordPress has a vulnerability that allows authenticated attackers with Subscriber-level access and above to exploit a PHP Object Injection issue. This occurs through the deserialization of untrusted input in the get_user_meta_fields_html function. Although no known PHP Object Pollution (POP) chain exists within the vulnerable software itself, the presence of a POP chain from other installed plugins or themes could grant attackers the ability to perform various malicious actions, including deleting files, retrieving sensitive information, or executing unauthorized code.
Affected Version(s)
ProfileGrid – User Profiles, Groups and Communities * <= 5.9.4.5
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nguyen Tan Phat