SecAlerts
profilegrid logo

profilegrid

Security Risk Profile

32
/100
low

Security Risk Score

Comprehensive risk assessment based on 17 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from May 2, 2024 to present

17
Total CVEs
4
Critical+High
0
Exploited
3
Unpatched

Threat Assessment

Avg CVSS
5.8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
3
Critical/High
Risk Level
32/100
low
🆕 2Fresh (<7d)📈 5 in Last 30 Days

Severity Distribution

Critical
0
High
4
Medium
11
Low
1

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
4

Age Distribution

Common Weaknesses (CWE)

1
XSS
1
2
SQL Injection
1
3
SSRF
1

Most Affected Products

1. Metagauss Profilegrid Wordpress10
2. ProfileGrid User Profiles, Groups and Communities6
3. ProfileGrid WordPress plugin5
4. ProfileGrid ProfileGrid – User Profiles, Groups and Communities2
5. ProfileGrid ProfileGrid – User Profiles, Groups and Communities (WordPress plugin)1

Recent Vulnerabilities

See more →
CVE-2026-16289
CVSS 4.3medium

ProfileGrid < 6.0.0.0 - Subscriber+ Group Join Request Disclosure via pm_get_all_requests_from_group

8/3/2026🔧 No Patch
CVE-2026-16291
unknown

ProfileGrid < 5.9.9.8 - Subscriber+ Arbitrary Notification Deletion via IDOR

8/2/2026🔧 No Patch
CVE-2026-12688
CVSS 6.5medium

ProfileGrid < 5.9.9.7 - Unauthenticated Payment Bypass and Forced Group Membership via PayPal IPN Forgery

7/24/2026🔧 No Patch
CVE-2026-12690
CVSS 3.8low

ProfileGrid < 5.9.9.7 - Subscriber+ Premium License Tampering via Missing Authorization

7/24/2026🔧 No Patch
CVE-2026-12689
CVSS 5.4medium

ProfileGrid < 5.9.9.7 - Subscriber+ Cross-User Private Message Thread Deletion and Tampering via Missing Authorization

7/24/2026🔧 No Patch
CVE-2026-4609
CVSS 7.1high

ProfileGrid <= 5.9.8.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Group Joining

5/13/2026🔧 No Patch
CVE-2026-4607
CVSS 4.3medium

ProfileGrid <= 5.9.8.4 - Missing Authorization to Authenticated (Subscriber+) Group Settings Modification

5/13/2026🔧 No Patch
CVE-2025-6977
CVSS 6.1EPSS 0%medium

ProfileGrid – User Profiles, Groups and Communities <= 5.9.5.4 - Reflected Cross-Site Scripting via 'pm_get_messenger_notification' function

7/16/2025🔧 No Patch
CVE-2025-0724
CVSS 8.8high

ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.5 - Authenticated (Subscriber+) PHP Object Injection

3/22/2025🔧 No Patch
CVE-2025-1408
CVSS 4.3medium

ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.4 - Missing Authorinzation to Authenticated (Subscriber+) Join Group Requests Management

3/22/2025🔧 No Patch

Monitor profilegrid in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

profilegrid Security Vulnerabilities & Risk Score | 17 CVEs | SecAlerts - SecAlerts