CVE-2026-25417: WordPress ProfileGrid plugin <= 5.9.8.1 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Stored XSS.This issue affects ProfileGrid : from n/a through <= 5.9.8.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25417?
CVE-2026-25417 is classified as a Cross Site Scripting (XSS) vulnerability which is considered critical due to its potential for exploitation.
How do I fix CVE-2026-25417?
To fix CVE-2026-25417, update the Metagauss ProfileGrid plugin to version 5.9.8.2 or later.
What type of vulnerability is CVE-2026-25417?
CVE-2026-25417 is a Stored Cross Site Scripting (XSS) vulnerability.
Which software is affected by CVE-2026-25417?
CVE-2026-25417 affects the Metagauss ProfileGrid plugin version 5.9.8.1 and earlier.
What could be the impact of CVE-2026-25417 if exploited?
Exploitation of CVE-2026-25417 could allow an attacker to inject malicious scripts into web pages viewed by users.