Reflected Cross-Site Scripting Vulnerability in ProfileGrid Plugin by WordPress
CVE-2025-6977

6.1MEDIUM

What is CVE-2025-6977?

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress contains a reflected cross-site scripting vulnerability. This flaw arises from inadequate input sanitization and output escaping in the 'pm_get_messenger_notification' function, affecting all versions up to and including 5.9.5.4. Unauthenticated attackers can exploit this vulnerability to inject arbitrary web scripts into pages, which may be executed when a logged-in user is tricked into clicking a malicious link. It is crucial for users of this plugin to apply security best practices and promptly update to mitigate risks associated with this vulnerability.

Affected Version(s)

ProfileGrid – User Profiles, Groups and Communities * <= 5.9.5.4

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kenneth Billones
.
CVE-2025-6977 : Reflected Cross-Site Scripting Vulnerability in ProfileGrid Plugin by WordPress