Description
Server-Side Request Forgery (SSRF) vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Server Side Request Forgery.This issue affects ProfileGrid : from n/a through <= 5.9.5.2.
Published: 2025-06-17
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A server‑side request forgery (SSRF) flaw exists in Metagauss ProfileGrid plugin version 5.9.5.2 and earlier, allowing an attacker to instruct the WordPress site to make arbitrary HTTP requests to internal or external endpoints. This can lead to leakage of sensitive data, port scanning, or further exploitation of services that the site can reach, thereby compromising confidentiality and potentially availability of network resources.

Affected Systems

The vulnerability affects the WordPress ProfileGrid plugin developed by Metagauss, specifically all releases from the initial version through 5.9.5.2. WordPress installations that have this plugin at or below that version are susceptible.

Risk and Exploitability

With a CVSS score of 4.9 the flaw is considered moderate in severity, but the EPSS score of less than 1% indicates a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog, further suggesting limited active exploitation reports. The likely attack vector is through the plugin’s functionality that accepts user‑supplied URLs, but the exact exploitation method was not detailed in the input.

Generated by OpenCVE AI on April 30, 2026 at 11:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ProfileGrid to a version newer than 5.9.5.2.
  • Ensure that all WordPress plugins are kept up to date and remove any unused instances of ProfileGrid.
  • Disable or limit the plugin’s ability to process external URLs by configuring network controls or firewall rules to block unintended internal requests.

Generated by OpenCVE AI on April 30, 2026 at 11:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-19223 Server-Side Request Forgery (SSRF) vulnerability in Metagauss ProfileGrid allows Server Side Request Forgery. This issue affects ProfileGrid : from n/a through 5.9.5.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Server-Side Request Forgery (SSRF) vulnerability in Metagauss ProfileGrid allows Server Side Request Forgery. This issue affects ProfileGrid : from n/a through 5.9.5.2. Server-Side Request Forgery (SSRF) vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Server Side Request Forgery.This issue affects ProfileGrid : from n/a through <= 5.9.5.2.
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Thu, 26 Jun 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 17 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Description Server-Side Request Forgery (SSRF) vulnerability in Metagauss ProfileGrid allows Server Side Request Forgery. This issue affects ProfileGrid : from n/a through 5.9.5.2.
Title WordPress ProfileGrid plugin <= 5.9.5.2 - Server Side Request Forgery (SSRF) Vulnerability
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:06.696Z

Reserved: 2025-06-11T16:06:15.666Z

Link: CVE-2025-49877

cve-icon Vulnrichment

Updated: 2025-06-26T17:51:42.969Z

cve-icon NVD

Status : Deferred

Published: 2025-06-17T15:15:52.270

Modified: 2026-04-23T15:31:46.080

Link: CVE-2025-49877

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T11:30:06Z

Weaknesses