CVE-2023-3714: ProfileGrid <= 5.5.2 - Missing Authorization to Arbitrary Group Option Modification and Privilege Escalation
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'editgroup' handler in versions up to, and including, 5.5.2. This makes it possible for authenticated attackers, with group ownership, to update group options, including the 'associaterole' parameter, which defines the member's role. This issue was partially patched in version 5.5.2 preventing privilege escalation, however, it was fully patched in 5.5.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress ProfileGrid pluginto a version that resolves this vulnerability.Fixed in 5.5.3
Event History
Frequently Asked Questions
What is the vulnerability ID for the ProfileGrid plugin for WordPress?
The vulnerability ID for the ProfileGrid plugin for WordPress is CVE-2023-3714.
What is the severity level of CVE-2023-3714?
The severity level of CVE-2023-3714 is high with a score of 8.8.
What is the affected software of CVE-2023-3714?
The affected software is the ProfileGrid plugin for WordPress versions up to, and including, 5.5.2.
How can authenticated attackers exploit this vulnerability?
Authenticated attackers, with group ownership, can exploit this vulnerability by updating group options, including unauthorized modification of data.
Is there a fix available for CVE-2023-3714?
Yes, please refer to the references provided for the fix to CVE-2023-3714.