First published: Thu May 02 2024(Updated: )
The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the pm_upload_cover_image function in all versions up to, and including, 5.8.3. This makes it possible for authenticated attackers, with subscriber access or higher, to delete attachments.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Metagauss ProfileGrid | <5.8.4 | |
ProfileGrid | <=5.8.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-3606 is rated as a high severity vulnerability due to the potential for unauthorized data deletion.
To fix CVE-2024-3606, update the ProfileGrid plugin to version 5.8.4 or later, which contains the necessary capability checks.
All versions of the ProfileGrid plugin up to and including 5.8.3 are affected by CVE-2024-3606.
Any WordPress installations using the ProfileGrid plugin prior to version 5.8.4 are at risk from CVE-2024-3606.
Unauthorized users can potentially delete data associated with user profiles due to the lack of a capability check in the affected function.