Impact
The vulnerability is present in the ProfileGrid WordPress plugin before version 5.9.9.7, where license‑management actions rely solely on a nonce that is exposed to any logged‑in user. No capability check is performed, so an authenticated user with Subscriber-level access or higher can overwrite the site’s premium license settings. This allows the user to disable or alter premium features, compromising the integrity of the plugin’s configuration and potentially disabling paid functionality. The likely attack vector is an authenticated user with Subscriber or above privileges.
Affected Systems
WordPress sites that have the ProfileGrid plugin version 5.9.9.6 or earlier are affected. Upgrading to version 5.9.9.7 or later resolves the missing authorization check and restores proper capability validation for license‑management operations.
Risk and Exploitability
The CVSS score of 3.8 indicates moderate risk, and the EPSS score below 1% implies low exploitation probability. The vulnerability is not included in the CISA KEV catalog. Because the vulnerability requires an authenticated user with at least Subscriber privileges, the attack vector is limited to legitimate site users rather than remote unauthenticated attackers. Exploitation involves submitting a request with the exposed nonce to the license‑management endpoint, bypassing the missing capability check and enabling unauthorized license changes.
OpenCVE Enrichment