The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.8.9. This is due to a lack of validation on user-supplied data in the 'pm_upload_image' AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update their user capabilities to Administrator.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-47515 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.8.9. This is due to a lack of validation on user-supplied data in the 'pm_upload_image' AJAX action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update their user capabilities to Administrator.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 10 Feb 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Metagauss
Metagauss profilegrid
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:metagauss:profilegrid:*:*:*:*:*:wordpress:*:*
Vendors & Products Metagauss
Metagauss profilegrid

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-08-01T21:41:03.291Z

Reserved: 2024-06-28T19:19:15.990Z

Link: CVE-2024-6411

cve-icon Vulnrichment

Updated: 2024-08-01T21:41:03.291Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-10T05:15:12.497

Modified: 2025-02-10T16:00:19.467

Link: CVE-2024-6411

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.