CVE-2026-62061: WordPress ProfileGrid plugin <= 6.0.0.2 - Insecure Direct Object References (IDOR) vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfileGrid: from n/a through 6.0.0.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
metagauss/profilegrid-user-profiles-groups-and-communitiesto a version that resolves this vulnerability.Fixed in 6.0.0.3
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The reported CVSS vector indicates that the issue can be exploited remotely without authentication or user interaction. Exploitation is rated low complexity.
What is the potential impact if exploitation succeeds?
The reported impact is limited to confidentiality, with low confidentiality impact and no reported integrity or availability impact. The issue is described as an authorization bypass through a user-controlled key.
Which ProfileGrid versions are affected?
ProfileGrid versions through 6.0.0.2 are affected. The affected version range begins at an unspecified earlier version.