Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 302 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
65 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.20% | — | Metagauss ProfilegridAI | 1/10/2026 | 1/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfileGrid: from n/a through 6.0.0.2. | |
| Aplazada | Media (5.3) | 0.35% | — | Metagauss ProfilegridAI | 6/8/2026 | 26/8/2026 | The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list, and registers the handler for unauthenticated users, allowing any unauthenticated visitor to disclose the members and their identifiers of any group, including private or closed ones, bypassing… | |
| Aplazada | Media (4.3) | 0.27% | — | Metagauss ProfilegridAI | 3/8/2026 | 26/8/2026 | The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user such as a Subscriber to disclose the names and request dates of the users awaiting approval to join any group, including private ones. | |
| Aplazada | Media (4.3) | 0.25% | — | Metagauss ProfilegridAI | 2/8/2026 | 26/8/2026 | The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user before deleting it, allowing any authenticated user such as a Subscriber to delete other users' notifications by enumerating notification identifiers. | |
| Aplazada | Alta (7.5) | 0.41% | — | Metagauss ProfilegridAI | 30/7/2026 | 30/7/2026 | The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into through its front-end registration, allowing unauthenticated users to register directly into a privileged group and be granted that group's configured role, up to Administrator when such a group exists,… | |
| Aplazada | Baja (3.8) | 0.26% | — | Metagauss ProfilegridAI | 24/7/2026 | 24/7/2026 | The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its license management actions, relying only on a nonce that is exposed to any logged-in user, allowing authenticated users with Subscriber-level access and above to overwrite the site's premium license settings. | |
| Aplazada | Media (5.4) | 0.23% | — | Metagauss ProfilegridAI | 24/7/2026 | 24/7/2026 | The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions, allowing authenticated users with Subscriber-level access and above to soft-delete, tamper with the metadata of, and mark as read other users' private message threads. | |
| Aplazada | Media (6.5) | 0.27% | — | Metagauss ProfilegridAI | 24/7/2026 | 24/7/2026 | The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group membership, allowing unauthenticated attackers to forge a payment notification and mark any user as a paid member of any group without any payment being made. | |
| Aplazada | Alta (7.5) | 0.48% | — | Metagauss ProfilegridAI | 13/7/2026 | 13/7/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Password Recovery Exploitation.This issue affects ProfileGrid : from n/a through <= 5.9.9.6. | |
| Aplazada | Media (4.3) | 0.34% | — | Profilegrid Memberships AND User Profiles FOR WoocommerceAI | 9/7/2026 | 9/7/2026 | The Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration plugin for WordPress is vulnerable to unauthorized plugin installation and activation in versions up to, and including, 3.4. This is due to a missing capability check and missing nonce validation on the pg_install_profilegrid()… | |
| Aplazada | Alta (8.8) | 0.20% | — | Metagauss ProfilegridAI | 2/7/2026 | 30/9/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Cross Site Request Forgery.This issue affects ProfileGrid: from n/a through 6.0.0.2. | |
| Aplazada | Crítica (9.8) | 0.53% | — | Metagauss ProfilegridAI | 30/6/2026 | 30/6/2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.9.9.5. This is due to the plugin not validating a `user_login` on registration forms that don't contain this parameter, and not properly… | |
| Aplazada | Media (6.4) | 0.35% | — | Metagauss ProfilegridAI | 23/6/2026 | 29/6/2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pm_author_message' parameter in the pm_send_message_to_author function in all versions up to, and including, 5.9.9.2 due to insufficient input sanitization and output escaping. This makes… | |
| Aplazada | Alta (7.1) | 0.38% | — | Metagauss ProfilegridAI | 13/5/2026 | 17/6/2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the pm_invite_user function in all versions up to, and including, 5.9.8.4. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Aplazada | Media (6.5) | 0.45% | — | Metagauss ProfilegridAI | 13/5/2026 | 17/6/2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind SQL Injection via the 'rid' parameter in all versions up to, and including, 5.9.8.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Aplazada | Media (4.3) | 0.39% | — | Metagauss ProfilegridAI | 13/5/2026 | 17/6/2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.9.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action via the pm_set_group_order, pm_set_group_items, and… | |
| Aplazada | Media (6.5) | 0.16% | — | Metagauss ProfilegridAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Stored XSS.This issue affects ProfileGrid : from n/a through <= 5.9.8.1. | |
| Aplazada | Media (4.3) | 0.13% | — | Metagauss ProfilegridAI | 7/3/2026 | 17/6/2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.9.8.2. This is due to missing nonce validation on the membership request management page (approve and decline actions). This makes it possible for… | |
| Aplazada | Media (4.3) | 0.22% | — | Metagauss ProfilegridAI | 7/3/2026 | 17/6/2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized message deletion due to a missing capability check on the pg_delete_msg() function in all versions up to, and including, 5.9.8.1. This is due to the function not verifying that the requesting user has permission… | |
| Aplazada | Media (5.3) | 0.36% | — | Metagauss ProfilegridAI | 5/2/2026 | 17/6/2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.7.2 via the 'pm_upload_image' and 'pm_upload_cover_image' AJAX actions. This is due to the update_user_meta() function being called outside of the… | |
| Aplazada | Media (4.3) | 0.32% | — | Metagauss ProfilegridAI | 5/2/2026 | 17/6/2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized user suspension due to a missing capability check on the pm_deactivate_user_from_group() function in all versions up to, and including, 5.9.7.2. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.1) | 0.24% | — | Metagauss ProfilegridAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Reflected XSS.This issue affects ProfileGrid : from n/a through <= 5.9.5.7. | |
| Aplazada | Alta (8.5) | 0.27% | — | Metagauss ProfilegridAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Blind SQL Injection.This issue affects ProfileGrid : from n/a through <= 5.9.5.3. | |
| Aplazada | Alta (8.5) | 0.34% | — | Metagauss ProfilegridAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows SQL Injection.This issue affects ProfileGrid : from n/a through <= 5.9.5.2. | |
| Analizada | Media (6.1) | 0.29% | — | Metagauss Profilegrid | 16/7/2025 | 17/6/2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘pm_get_messenger_notification’ function in all versions up to, and including, 5.9.5.4 due to insufficient input sanitization and output escaping. This makes it possible for… |