CVE-2025-49877: WordPress ProfileGrid plugin <= 5.9.5.2 - Server Side Request Forgery (SSRF) Vulnerability
Server-Side Request Forgery (SSRF) vulnerability in Metagauss ProfileGrid allows Server Side Request Forgery. This issue affects ProfileGrid : from n/a through 5.9.5.2.
Other sources
Server-Side Request Forgery (SSRF) vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Server Side Request Forgery.This issue affects ProfileGrid : from n/a through <= 5.9.5.2.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49877?
CVE-2025-49877 is classified as a Server-Side Request Forgery (SSRF) vulnerability, which can lead to serious security risks.
How do I fix CVE-2025-49877?
To fix CVE-2025-49877, update Metagauss ProfileGrid to version 5.9.5.3 or later.
What versions of Metagauss ProfileGrid are affected by CVE-2025-49877?
CVE-2025-49877 affects Metagauss ProfileGrid versions from n/a through 5.9.5.2.
Can CVE-2025-49877 be exploited remotely?
Yes, CVE-2025-49877 can be exploited remotely due to its nature as an SSRF vulnerability.
Is CVE-2025-49877 an issue for developers using ProfileGrid?
Yes, developers using ProfileGrid versions prior to 5.9.5.3 should take immediate action to mitigate CVE-2025-49877.