PT-2026-23816 · WordPress · Profilegrid – User Profiles

Boris Bogosavac

+1

·

Publicado

2026-03-07

·

Atualizado

2026-03-07

·

CVE-2026-2488

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions ProfileGrid – User Profiles, Groups and Communities plugin for WordPress versions up to and including 5.9.8.1
Description The ProfileGrid plugin for WordPress is affected by an issue allowing unauthorized message deletion. This occurs because the pg delete msg() function lacks a proper capability check, enabling authenticated attackers with Subscriber-level access or higher to delete messages belonging to any user. Exploitation involves sending a direct request with a valid message ID through the mid parameter.
Recommendations Update ProfileGrid – User Profiles, Groups and Communities plugin for WordPress to a version later than 5.9.8.1.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-2488

Produtos afetados

Profilegrid – User Profiles