CVE-2022-36352: WordPress ProfileGrid Plugin <= 5.0.3 is vulnerable to Broken Access Control
Published Jan 8, 2024
·Updated
Missing Authorization vulnerability in Profilegrid ProfileGrid – User Profiles, Memberships, Groups and Communities.This issue affects ProfileGrid – User Profiles, Memberships, Groups and Communities: from n/a through 5.0.3.
Affected Software
1 affected component
Metagauss Profilegrid Wordpress<=5.0.3
Remediation
Information
Update to 5.0.4 or a higher version.
Event History
Jan 8, 2024
CVE Published
via MITRE·09:50 PM
Data Sourced
via MITRE·09:50 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-36352?
The severity of CVE-2022-36352 is rated as high due to its potential for unauthorized access.
2
How do I fix CVE-2022-36352?
To fix CVE-2022-36352, update the ProfileGrid plugin to version 5.0.4 or later to address the missing authorization issue.
3
Which versions are affected by CVE-2022-36352?
CVE-2022-36352 affects all versions of ProfileGrid from launch up to and including version 5.0.3.
4
What type of vulnerability is CVE-2022-36352?
CVE-2022-36352 is categorized as a Missing Authorization vulnerability.
5
Who is affected by CVE-2022-36352?
Users of the ProfileGrid – User Profiles, Memberships, Groups and Communities plugin prior to version 5.0.4 are at risk from CVE-2022-36352.