Impact
The vulnerability involves a missing authorization check in the Metagauss ProfileGrid plugin. Incorrectly configured access control security levels allow attackers to bypass intended restrictions, potentially gaining unauthorized access to user profiles or administrative functions. This flaw can result in data exposure or privilege escalation within the WordPress environment, especially if sensitive user information is exposed.
Affected Systems
Metagauss’s ProfileGrid plugin for WordPress, versions up to and including 5.9.5.1, are affected. The issue applies to all installations of the plugin from the earliest known release through 5.9.5.1. Only the ProfileGrid product is impacted; no other Metagauss plugins or WordPress components are directly referenced.
Risk and Exploitability
The reported CVSS score of 4.3 suggests a low to moderate severity, and the EPSS score of less than 1% indicates a very low likelihood of exploitation from the attacker’s perspective. The bug is not currently listed in CISA’s KEV catalog. The most likely attack vector is through the web interface or API endpoints exposed by the plugin; an attacker with access to the site could craft requests that exploit the missing authorization check and retrieve or modify content beyond their permissions.
OpenCVE Enrichment
EUVD