Impact
An unauthenticated Cross‑Site Request Forgery flaw in the WordPress ProfileGrid plugin, affecting all releases up to and including 5.9.9.7, is a CWE‑352 vulnerability. It allows an attacker to craft and send an HTTP request that the plugin accepts without the presence of a valid user session. This vulnerability enables the attacker to perform any action that a logged‑in user could, such as changing account credentials or modifying profile information, thereby resulting in potential account takeover.
Affected Systems
The vulnerability is found in the ProfileGrid plugin distributed by Metagauss. WordPress installations that have this plugin activated and are running version 5.9.9.7 or older are at risk. Any site that includes the vulnerable plugin code is potentially exposed.
Risk and Exploitability
The CVSS score of 8.8 classifies the issue as high severity. The EPSS score of <1% indicates a low likelihood of exploitation, but the possibility of remote account takeover justifies attention. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves a victim’s browser unintentionally submitting a crafted request—such as clicking a malicious link—while a valid session cookie remains in the browser, allowing the unauthenticated CSRF to succeed.
OpenCVE Enrichment