Authentication Bypass Vulnerability in Metagauss ProfileGrid Plugin
CVE-2026-57697

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 July 2026

What is CVE-2026-57697?

An authentication bypass vulnerability exists in the Metagauss ProfileGrid plugin for WordPress, specifically allowing attackers to exploit password recovery features. This vulnerability enables unauthorized users to gain access to sensitive user data by leveraging an alternate path or channel that bypasses standard authentication controls. Affected versions of ProfileGrid include all versions up to and including 5.9.9.6, posing a risk to users who have not updated their installations.

Affected Version(s)

ProfileGrid 0 <= 5.9.9.6

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jakub Herman | Patchstack Bug Bounty Program
.