CVE-2025-48079: WordPress ProfileGrid plugin <= 5.9.5.1 - Broken Access Control Vulnerability
Missing Authorization vulnerability in Metagauss ProfileGrid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ProfileGrid : from n/a through 5.9.5.1.
Other sources
Missing Authorization vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfileGrid : from n/a through <= 5.9.5.1.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48079?
CVE-2025-48079 is classified as a missing authorization vulnerability that can lead to unauthorized access due to incorrectly configured access control security levels.
How do I fix CVE-2025-48079?
To fix CVE-2025-48079, ensure that access control settings in Metagauss ProfileGrid are properly configured and upgraded to a patched version beyond 5.9.5.1.
What versions of ProfileGrid are affected by CVE-2025-48079?
CVE-2025-48079 affects all versions of Metagauss ProfileGrid from n/a through 5.9.5.1.
What impact does CVE-2025-48079 have on user data?
CVE-2025-48079 can potentially expose sensitive user data by allowing unauthorized users to bypass access controls.
Is there a workaround for CVE-2025-48079?
While upgrading is recommended, a possible workaround may involve manually adjusting access control settings to restrict unauthorized access until a patch is implemented.