Impact
The vulnerability allows an attacker to bypass normal authentication by exploiting an alternate password recovery channel. When triggered, an attacker can reset a user’s password without having prior knowledge of the user’s credentials, leading to unauthorized access to WordPress accounts and the data they can reach. This issue is identified as a CWE-288, an Authentication Bypass weakness that directly compromises confidentiality and integrity of the system.
Affected Systems
The flaw affects the Metagauss ProfileGrid plugin for WordPress, version 5.9.9.6 and earlier. Users who have not upgraded beyond this release are vulnerable. No specific operating system or WordPress core version limitations are listed.
Risk and Exploitability
The CVSS score of 7.5 reflects a significant threat level. The EPSS score being below 1% suggests that exploitation probability is currently low, and the flaw is not listed in the CISA KEV catalog. Nonetheless, the ability to reset passwords without authentication makes the vulnerability a high‑risk vector for credential compromise. Based on the description, it is inferred that attackers could leverage the web interface’s password recovery feature to launch the exploit remotely, reachable endpoints and no additional mitigations.
OpenCVE Enrichment