ProfileGrid
cpe:2.3:a:profilegrid:profilegrid:*:*:*:*:wordpress:*:*
- <= 5.9.4.2
A limited server-side request forgery (SSRF) vulnerability has been identified in the ProfileGrid – User Profiles, Groups and Communities plugin for WordPress, affecting all versions through 5.9.4.2. The vulnerability arises in the pm_upload_image function, allowing authenticated attackers with Subscriber-level access and above to send web requests to arbitrary locations. This could be exploited to download and view images or to check the existence of non-image files, both on local and remote hosts.
Exploitation of this vulnerability could lead to unauthorized web requests being made from the WordPress application, potentially allowing attackers to access or manipulate files on local or remote servers.
Users are advised to update the ProfileGrid – User Profiles, Groups and Communities plugin to version 5.9.4.3 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.