Pricing
Case studies
Login
Start trial
ProfileGrid
Metagauss
Developer
5.9.8.5
Latest version
6,000
Installations
No date
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
0 present
50 patched
25 Mitigation rules
Cross Site Scripting (XSS) vulnerability
<= 5.9.8.1
23/03/2026
Missing Authorization to Authenticated (Subscriber+) Arbitrary Message Deletion vulnerability
<= 5.9.8.1
07/03/2026
Cross-Site Request Forgery to Group Membership Request Approval/Denial vulnerability
<= 5.9.8.2
07/03/2026
Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Profile and Cover Image Modification vulnerability
<= 5.9.7.2
04/02/2026
WordPress ProfileGrid - User Profiles, Groups and Communities plugin <= 5.9.7.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Suspension vulnerability
<= 5.9.7.2
04/02/2026
Missing Authorinzation to Authenticated (Subscriber+) Join Group Requests Management vulnerability
<= 5.9.4.4
31/12/2025
Authenticated (Subscriber+) PHP Object Injection vulnerability
<= 5.9.4.5
31/12/2025
Reflected Cross Site Scripting (XSS) vulnerability
<= 5.9.5.7
01/09/2025
SQL Injection vulnerability
<= 5.9.5.3
24/07/2025
Reflected Cross-Site Scripting via 'pm_get_messenger_notification' function vulnerability
<= 5.9.5.4
16/07/2025
SQL Injection vulnerability
<= 5.9.5.2
10/07/2025
Full Path Disclosure (FPD) Vulnerability
<= 5.9.5.2
19/06/2025
Server Side Request Forgery (SSRF) Vulnerability
<= 5.9.5.2
12/06/2025
Broken Access Control Vulnerability
<= 5.9.5.1
16/05/2025
SQL Injection Vulnerability
<= 5.9.5.0
12/05/2025
SQL Injection Vulnerability
<= 5.9.4.8
17/04/2025
Authenticated (Subscriber+) SQL Injection vulnerability
<= 5.9.4.7
21/03/2025
PHP Object Injection vulnerability
<= 5.9.4.3
23/02/2025
Insecure Direct Object Reference to Authenticated (Subscriber+) Private Messages Disclosure vulnerability
<= 5.9.4.2
17/02/2025
Authenticated (Subscriber+) Limited Server-Side Request Forgery vulnerability
<= 5.9.4.2
17/02/2025
Missing Authorization to Authenticated (Subscriber+) Arbitrary User Meta Deletion vulnerability
<= 5.9.3.6
19/11/2024
Cross Site Request Forgery (CSRF) vulnerability
<= 5.9.3
14/10/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.9.3.2
26/09/2024
Authenticated (Subscriber+) Insecure Direct Object Reference vulnerability
<= 5.8.9
10/07/2024
Authenticated Privilege Escalation vulnerability
<= 5.8.9
09/07/2024
Broken Access Control vulnerability
<= 5.8.7
01/07/2024
Missing Authorization vulnerability
<= 5.8.6
05/06/2024
Insecure Direct Object Reference (IDOR) vulnerability
<= 5.7.9
22/04/2024
Group Members Limit Bypass vulnerability
<= 5.8.2
22/04/2024
Insecure Direct Object References (IDOR) vulnerability
<= 5.7.9
22/04/2024
Missing Authorization vulnerability
<= 5.8.3
17/04/2024
Cross Site Request Forgery (CSRF) vulnerability
<= 5.7.8
08/04/2024
IDOR on Friend Request vulnerability
<= 5.7.6
05/04/2024
Insecure Direct Object References (IDOR) vulnerability
<= 5.7.2
28/03/2024
SQL Injection vulnerability
<= 5.7.8
28/03/2024
SQL Injection vulnerability
<= 5.7.8
28/03/2024
Contributor+ SQL Injection vulnerability
<= 5.7.1
26/03/2024
Broken Access Control vulnerability
<= 5.6.6
28/12/2023
Cross Site Request Forgery (CSRF) vulnerability
<= 5.7.1
07/11/2023
Authenticated (Subscriber+) Arbitrary Option Update vulnerability
<= 5.5.1
18/07/2023
Hardcoded Encryption Key vulnerability
<= 5.5.0
18/07/2023
Missing Authorization to Arbitrary Group Option Modification and Privilege Escalation vulnerability
<= 5.5.2
18/07/2023
Missing Authorization to User Import vulnerability
<= 5.5.1
18/07/2023
Broken Access Control vulnerability
<= 5.0.3
16/03/2023
Subscriber+ Arbitrary Password Reset vulnerability
< 5.3.1
02/03/2023
Auth. CSV Injection vulnerability
<= 5.1.6
17/11/2022
Reflected Cross-Site Scripting (XSS) vulnerability
<= 5.1.0
15/11/2022
Authenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 4.7.4
18/01/2022
Authenticated Code Execution vulnerability
<= 2.8.5
05/06/2018
Reflected Cross Site Scripting
<= 2.6.6
27/11/2017