Where
-Infinity
0

Metagauss RegistrationMagicWordPress RegistrationMagic plugin <= 6.0.7.6 - Broken Access Control vulnerability

Risk 43
Severity
7.5
First published (updated )

Metagauss ProfileGrid (profilegrid-user-profiles-groups-and-communities)WordPress ProfileGrid plugin <= 5.9.8.1 - Cross Site Scripting (XSS) vulnerability

Risk 46
Severity
6.5
First published (updated )

Metagauss EventPrimeWordPress EventPrime plugin <= 4.2.8.0 - PHP Object Injection vulnerability

Risk 86
Severity
9.8
First published (updated )

Metagauss RegistrationMagicWordPress RegistrationMagic plugin <= 6.0.7.1 - Account Takeover vulnerability

Risk 75
Severity
8.1
First published (updated )

Metagauss EventPrime (eventprime-event-calendar-management)WordPress EventPrime plugin <= 4.2.6.0 - Broken Access Control vulnerability

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Metagauss EventPrime (eventprime-event-calendar-management) WordPress pluginWordPress EventPrime plugin <= 4.2.8.3 - Payment Bypass vulnerability

Risk 35
Severity
7.5
First published (updated )

Metagauss EventPrimeWordPress EventPrime plugin <= 4.2.8.0 - Broken Access Control vulnerability

Risk 19
Severity
5.3
EPSS
0.04%
First published (updated )

Metagauss EventPrimeWordPress EventPrime plugin <= 4.2.4.1 - Broken Access Control vulnerability

Risk 22
Severity
4.3
First published (updated )

Metagauss EventPrimeWordPress EventPrime plugin <= 4.2.4.1 - Sensitive Data Exposure vulnerability

Risk 22
Severity
4.3
First published (updated )

RegistrationMagic Custom Registration FormsRegistrationMagic - Custom Registration Forms <= 3.7.9.2 - PHP Object Injection

Risk 86
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Metagauss ProfileGridWordPress ProfileGrid plugin <= 5.9.5.3 - SQL Injection vulnerability

Risk 55
Severity
8.5
First published (updated )

ProfileGrid User Profiles, Groups and CommunitiesProfileGrid – User Profiles, Groups and Communities <= 5.9.5.4 - Reflected Cross-Site Scripting via 'pm_get_messenger_notification' function

Risk 27
Severity
6.1
EPSS
0.14%
First published (updated )

WordPress Download PluginDownload Plugin <= 2.2.8 - Authenticated (Administrator+) Arbitrary File Upload

Risk 49
Severity
7.2
EPSS
0.11%
First published (updated )

Metagauss ProfileGridWordPress ProfileGrid plugin <= 5.9.5.2 - Full Path Disclosure (FPD) Vulnerability

Risk 17
Severity
4.3
EPSS
0.03%
First published (updated )

Metagauss ProfileGridWordPress ProfileGrid plugin <= 5.9.5.2 - Server Side Request Forgery (SSRF) Vulnerability

Risk 24
Severity
4.9
EPSS
0.03%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Metagauss ProfileGridWordPress ProfileGrid plugin <= 5.9.5.0 - SQL Injection Vulnerability

Risk 40
Severity
8.5
EPSS
0.03%
First published (updated )

Metagauss ProfileGridWordPress ProfileGrid plugin <= 5.9.5.1 - Broken Access Control Vulnerability

Risk 16
Severity
4.3
EPSS
0.03%
First published (updated )

EventPrime Events Calendar, Bookings and TicketsEventPrime – Events Calendar, Bookings and Tickets < 3.5.0 - Subscriber+ Arbitrary booking settings update

Risk 39
Severity
6.4
First published (updated )

RegistrationMagic WordPress pluginRegistrationMagic < 6.0.2.1 - Stored XSS

Risk 29
Severity
4.8
First published (updated )

Metagauss ProfileGridWordPress ProfileGrid plugin <= 5.9.4.8 - SQL Injection Vulnerability

Risk 40
Severity
8.5
EPSS
0.03%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

ProfileGrid User Profiles, Groups and CommunitiesProfileGrid – User Profiles, Groups and Communities <= 5.9.4.5 - Authenticated (Subscriber+) PHP Object Injection

Risk 79
Severity
8.8
First published (updated )

ProfileGrid User Profiles, Groups and CommunitiesProfileGrid – User Profiles, Groups and Communities <= 5.9.4.4 - Missing Authorinzation to Authenticated (Subscriber+) Join Group Requests Management

Risk 22
Severity
4.3
First published (updated )

ProfileGrid User Profiles, Groups and CommunitiesProfileGrid – User Profiles, Groups and Communities <= 5.9.4.7 - Authenticated (Subscriber+) SQL Injection

Risk 38
Severity
6.5
First published (updated )

EventPrime Events Calendar, Bookings and TicketsEventPrime – Events Calendar, Bookings and Tickets <= 4.0.7.3 - Missing Authorization to Authenticated (Subscriber+) Event Attendees Export

Risk 22
Severity
4.3
First published (updated )

ProfileGrid User Profiles, Groups and CommunitiesProfileGrid – User Profiles, Groups and Communities <= 5.9.4.2 - Insecure Direct Object Reference to Authenticated (Subscriber+) Private Messages Disclosure

Risk 22
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

ProfileGrid User Profiles, Groups and CommunitiesProfileGrid – User Profiles, Groups and Communities <= 5.9.4.2 - Authenticated (Subscriber+) Limited Server-Side Request Forgery

Risk 34
Severity
5.4
First published (updated )

Metagauss Event Kikfyre (kikfyre-events-calendar-tickets)WordPress Event Kikfyre plugin <= 2.1.8 - Broken Access Control vulnerability

Risk 22
Severity
5.4
EPSS
0.04%
First published (updated )

Metagauss Registrationmagic WordpressWordPress RegistrationMagic Plugin <= 6.0.3.3 - Reflected Cross Site Scripting (XSS) vulnerability

Risk 27
Severity
7.1
EPSS
0.05%
First published (updated )

Metagauss Eventprime WordpressEventPrime – Events Calendar, Bookings and Tickets <= 4.0.7.3 - Unauthenticated Stored Cross-Site Scripting via Ticket Category and Ticket Type Name

Risk 45
Severity
7.2
First published (updated )

Metagauss Registrationmagic WordpressWordPress RegistrationMagic plugin <= 5.2.3.0 - Broken Access Control vulnerability

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203