Description
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_decline_join_group_request and pm_approve_join_group_request functions in all versions up to, and including, 5.9.4.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to approve or decline join group requests which is normally should be available to administrators only.
Problem types
Product status
* (semver)
Timeline
| 2025-02-16: | Discovered |
| 2025-03-21: | Disclosed |
Credits
Nguyen Tan Phat
References
www.wordfence.com/...-83ba-45c2-b3e1-1ce19f86eac7?source=cve
plugins.trac.wordpress.org/...class-profile-magic-public.php
plugins.trac.wordpress.org/...class-profile-magic-public.php
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.