Profilegrid WooCommerce Integration
- <= 3.4
A vulnerability exists in the WordPress ProfileGrid WooCommerce Integration plugin, specifically in versions through 3.4. The issue stems from a lack of proper capability checks and nonce validation in the 'pg_install_profilegrid' AJAX handler. This flaw allows authenticated users with Subscriber-level access and above to install and activate the ProfileGrid plugin without authorization.
Exploitation of this vulnerability allows for unauthorized installation and activation of the ProfileGrid plugin, which could lead to further unauthorized actions depending on the capabilities granted by the activated plugin.
To reproduce this vulnerability, an authenticated user with Subscriber-level access or higher can send a request to the 'pg_install_profilegrid' AJAX action. This request can be made without the necessary nonce for verification, bypassing the intended security measures. Once the request is processed, the ProfileGrid plugin will be installed and activated on the WordPress site.
Users are advised to update the ProfileGrid WooCommerce Integration plugin to version 3.4.1 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.