First published: Mon Mar 03 2025(Updated: )
Deserialization of Untrusted Data vulnerability in Metagauss ProfileGrid allows Object Injection. This issue affects ProfileGrid : from n/a through 5.9.4.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
ProfileGrid | >=n/a<=5.9.4.3 | |
WordPress ProfileGrid | <=5.9.4.3 |
Update the WordPress ProfileGrid wordpress plugin to the latest available version (at least 5.9.4.4).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26999 has been classified as a critical vulnerability due to its potential for object injection attacks.
To fix CVE-2025-26999, update Metagauss ProfileGrid to the latest version above 5.9.4.3.
CVE-2025-26999 affects Metagauss ProfileGrid versions n/a through 5.9.4.3 and the corresponding WordPress ProfileGrid Plugin.
CVE-2025-26999 is a Deserialization of Untrusted Data vulnerability, allowing for object injection.
Yes, CVE-2025-26999 can be exploited remotely if an attacker successfully manipulates the deserialization process.