Description
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized user suspension due to a missing capability check on the pm_deactivate_user_from_group() function in all versions up to, and including, 5.9.7.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to suspend arbitrary users from groups, including administrators, via the pm_deactivate_user_from_group AJAX action.
Problem types
Product status
* (semver)
Timeline
| 2026-01-23: | Vendor Notified |
| 2026-02-04: | Disclosed |
Credits
Athiwat Tiprasaharn
References
www.wordfence.com/...-f258-43ea-8db2-8d98ad7014d1?source=cve
plugins.trac.wordpress.org/...class-profile-magic-public.php
plugins.trac.wordpress.org/...class-profile-magic-public.php
plugins.trac.wordpress.org/...munities&sfp_email=&sfph_mail=