CVE-2025-49033: WordPress ProfileGrid plugin <= 5.9.5.3 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid allows Blind SQL Injection. This issue affects ProfileGrid : from n/a through 5.9.5.3.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Blind SQL Injection.This issue affects ProfileGrid : from n/a through <= 5.9.5.3.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49033?
CVE-2025-49033 has a high severity rating due to its ability to allow blind SQL Injection, which can lead to unauthorized data access.
How do I fix CVE-2025-49033?
To fix CVE-2025-49033, you should upgrade Metagauss ProfileGrid to the latest version beyond 5.9.5.3 where the vulnerability is patched.
Who is affected by CVE-2025-49033?
CVE-2025-49033 affects users of Metagauss ProfileGrid and WordPress ProfileGrid versions up to 5.9.5.3.
What types of attacks are possible with CVE-2025-49033?
CVE-2025-49033 allows attackers to perform blind SQL Injection attacks, potentially compromising the database.
Is CVE-2025-49033 being actively exploited?
While it is uncertain if CVE-2025-49033 is actively being exploited, its nature makes it a significant risk if left unaddressed.