Impact
The ProfileGrid WordPress plugin before version 6.0.0.0 fails to perform authorization checks before returning a group's member list. The handler is registered for unauthenticated requests, allowing any visitor to retrieve the members and identifiers of any group, including those that are private or closed. This results in a privacy breach where sensitive membership information is exposed without consent and bypasses the plugin’s intended visibility controls.
Affected Systems
WordPress sites that have installed the ProfileGrid plugin with any version lower than 6.0.0.0 are affected. The vulnerability applies to all such installations, regardless of the number or type of groups present.
Risk and Exploitability
The flaw can be exploited by simply accessing a URL exposed by the plugin; no authentication or special privileges are required. Although no CVSS score is supplied, the ease of exploitation combined with the confidentiality impact suggests a high risk. With EPSS not available and KEV not listed, the threat remains primarily from accidental or intentional data disclosure rather than active exploitation.
OpenCVE Enrichment