Impact
The ProfileGrid – User Profiles, Groups and Communities plugin allows an unauthenticated attacker to change the email address associated with the user whose ID is 1, which is typically the site administrator. The vulnerability stems from the plugin failing to validate the user_login parameter on certain registration forms and improperly handling error messages. By modifying the email of this privileged account, the attacker can trigger a password reset workflow to obtain the administrator's credentials. The weakness involves an error in input validation and error handling, identified as CWE-639.
Affected Systems
WordPress sites running the ProfileGrid plugin, version 5.9.9.5 or earlier, including all releases up to that point. The affected product is developed by Metagauss and distributed under the ProfileGrid plugin name.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.8, indicating a critical severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. The expected attack path requires no authentication; an attacker can craft a request to the plugin’s registration endpoint to overwrite the administrator’s email and then exploit the standard WordPress password‑reset mechanism. Given the absence of builtin mitigations, the risk of exploitation is high if an attacker knows the site’s URL.
OpenCVE Enrichment