Authorization Bypass in Metagauss ProfileGrid User Profiles Plugin
CVE-2026-62061
5.3MEDIUM
What is CVE-2026-62061?
A critical vulnerability exists in the Metagauss ProfileGrid User Profiles plugin that allows unauthorized access due to incorrectly configured access controls. This flaw enables attackers to exploit user-controlled keys, potentially bypassing security measures intended to restrict access to user profiles, groups, and communities. This issue particularly affects versions of ProfileGrid up to 6.0.0.2 and poses a significant risk to user data integrity and privacy.
Affected Version(s)
ProfileGrid 0 <= 6.0.0.2