Authorization Bypass in ProfileGrid User Profiles Plugin for WordPress
CVE-2026-4607

4.3MEDIUM

What is CVE-2026-4607?

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress contains an authorization bypass vulnerability that affects all versions up to and including 5.9.8.4. This vulnerability arises from the failure of the plugin to adequately verify user authorizations when performing certain actions through AJAX calls, specifically pm_set_group_order, pm_set_group_items, and pm_set_field_order. As a result, authenticated users, holding a Subscriber-level role or above, can gain unauthorized access to modify crucial group settings such as the order of menu items, group display options, and field arrangements, thereby compromising the overall integrity and security of the affected WordPress sites.

Affected Version(s)

ProfileGrid – User Profiles, Groups and Communities 0 <= 5.9.8.4

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chawabhon Netisingha
.