Blind SQL Injection Vulnerability in ProfileGrid Plugin for WordPress
CVE-2026-4608
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 May 2026
What is CVE-2026-4608?
The ProfileGrid plugin for WordPress is susceptible to a blind SQL injection vulnerability through the 'rid' parameter. This issue arises from inadequate escaping of user-supplied data and insufficient preparation of SQL queries, allowing authenticated users with Subscriber-level access or higher to manipulate existing SQL queries. Attackers can exploit this vulnerability to inject additional SQL commands, potentially compromising sensitive data stored in the database.
Affected Version(s)
ProfileGrid β User Profiles, Groups and Communities 0 <= 5.9.8.4