Reflected Cross-Site Scripting Vulnerability in ProfileGrid Plugin by WordPress
CVE-2025-6977
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 July 2025
What is CVE-2025-6977?
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress contains a reflected cross-site scripting vulnerability. This flaw arises from inadequate input sanitization and output escaping in the 'pm_get_messenger_notification' function, affecting all versions up to and including 5.9.5.4. Unauthenticated attackers can exploit this vulnerability to inject arbitrary web scripts into pages, which may be executed when a logged-in user is tricked into clicking a malicious link. It is crucial for users of this plugin to apply security best practices and promptly update to mitigate risks associated with this vulnerability.
Affected Version(s)
ProfileGrid – User Profiles, Groups and Communities * <= 5.9.5.4