Description
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.9.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action via the pm_set_group_order, pm_set_group_items, and pm_set_field_order AJAX actions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify site-wide ProfileGrid group settings including group menu order, group list order, group icon display, and field ordering.
Published: 2026-05-13
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress contains an authorization bypass that enables authenticated users with at least Subscriber level to use the pm_set_group_order, pm_set_group_items, and pm_set_field_order AJAX actions without proper permission checks. This flaw permits attackers to change group menu order, group list order, group icon display, and field ordering across the site, affecting both the appearance and functionality of the community features. The weakness is a classic missing‑authorization flaw, corresponding to CWE‑862, where the plugin fails to verify that the user has the right to perform the action. The resulting impact is a degradation of the site’s integrity and potential manipulation of user interaction flow.

Affected Systems

The vulnerability affects the MetaGauss ProfileGrid plugin for WordPress, in all releases up to and including version 5.9.8.4. No specific WordPress core versions are mentioned, so any WordPress installation using one of these plugin versions is potentially impacted. The issue is specific to the plugin’s admin area and its AJAX handlers; regular visitors are not affected.

Risk and Exploitability

The assigned CVSS score of 4.3 indicates moderate severity, reflecting that the flaw requires a logged‑in user with Subscriber level access, which is a common role. Because the EPSS score is not available, the current exploitation probability cannot be quantified, but the lack of a KEV listing suggests that no large‑scale exploit activity has been reported yet. Nonetheless, the flare‑increases risk if the site allows unauthenticated users to assume a Subscriber role via other means, or if a malicious user is promoted. A direct attack would involve authenticating as a subscriber and then invoking one of the AJAX actions to reorder groups or fields, which could alter the user interface and potentially hide or expose content depending on the site’s configuration.

Generated by OpenCVE AI on May 13, 2026 at 15:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the ProfileGrid plugin to a version newer than 5.9.8.4, which includes the authorization check for the affected AJAX actions.
  • Configure WordPress role capabilities so that only Administrators can assign or modify the settings that control group ordering and field placement, reducing the attack surface for Subscriber users.
  • If upgrading immediately is not possible, restrict access to the AJAX endpoints for non‑admin roles using a firewall or security plugin, and audit any existing changes to group and field orders to detect unauthorized modifications.

Generated by OpenCVE AI on May 13, 2026 at 15:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 13 May 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Metagauss
Metagauss profilegrid – User Profiles, Groups And Communities
Wordpress
Wordpress wordpress
Vendors & Products Metagauss
Metagauss profilegrid – User Profiles, Groups And Communities
Wordpress
Wordpress wordpress

Wed, 13 May 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 13 May 2026 14:15:00 +0000

Type Values Removed Values Added
Description The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.9.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action via the pm_set_group_order, pm_set_group_items, and pm_set_field_order AJAX actions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify site-wide ProfileGrid group settings including group menu order, group list order, group icon display, and field ordering.
Title ProfileGrid <= 5.9.8.4 - Missing Authorization to Authenticated (Subscriber+) Group Settings Modification
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Metagauss Profilegrid – User Profiles, Groups And Communities
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-05-13T14:44:55.586Z

Reserved: 2026-03-23T03:10:16.876Z

Link: CVE-2026-4607

cve-icon Vulnrichment

Updated: 2026-05-13T14:44:53.073Z

cve-icon NVD

Status : Deferred

Published: 2026-05-13T14:17:58.057

Modified: 2026-05-13T14:43:46.717

Link: CVE-2026-4607

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-13T16:00:17Z

Weaknesses