CVE-2025-6977: ProfileGrid – User Profiles, Groups and Communities <= 5.9.5.4 - Reflected Cross-Site Scripting via 'pm_get_messenger_notification' function
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘pmgetmessengernotification’ function in all versions up to, and including, 5.9.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a logged-in user into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6977?
CVE-2025-6977 is rated as a high-severity vulnerability due to the potential for reflected cross-site scripting attacks.
How do I fix CVE-2025-6977?
To fix CVE-2025-6977, update the ProfileGrid – User Profiles, Groups and Communities plugin to version 5.9.5.5 or higher.
What are the risks associated with CVE-2025-6977?
The risks associated with CVE-2025-6977 include the potential for attackers to execute malicious scripts in the context of a user’s session.
Who is affected by CVE-2025-6977?
All users of the ProfileGrid – User Profiles, Groups and Communities plugin for WordPress up to and including version 5.9.5.4 are affected by CVE-2025-6977.
What is the nature of the vulnerability in CVE-2025-6977?
CVE-2025-6977 is a reflected cross-site scripting vulnerability caused by inadequate input sanitization and output escaping.