CVE-2026-4607: ProfileGrid <= 5.9.8.4 - Missing Authorization to Authenticated (Subscriber+) Group Settings Modification
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.9.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action via the pmsetgrouporder, pmsetgroupitems, and pmsetfieldorder AJAX actions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify site-wide ProfileGrid group settings including group menu order, group list order, group icon display, and field ordering.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4607?
CVE-2026-4607 is considered a medium severity vulnerability due to the risk of unauthorized access to group settings.
How do I fix CVE-2026-4607?
To fix CVE-2026-4607, update the ProfileGrid plugin to version 5.9.8.5 or later.
What types of attacks can CVE-2026-4607 facilitate?
CVE-2026-4607 can facilitate unauthorized modifications to group settings by authenticated users.
Which versions of ProfileGrid are affected by CVE-2026-4607?
All versions of ProfileGrid up to and including 5.9.8.4 are affected by CVE-2026-4607.
Who is impacted by CVE-2026-4607?
Users of the ProfileGrid plugin for WordPress, specifically those using versions up to 5.9.8.4, are impacted by CVE-2026-4607.