ProfileGrid < 6.0.0.0 - Unauthenticated Group Member List Disclosure via pm_get_all_users_from_group
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 5.3epss 0.2%
exploitation probability
0.2%top 89% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list, and registers the handler for unauthenticated users, allowing any unauthenticated visitor to disclose the members and their identifiers of any group, including private or closed ones, bypassing the ProfileGrid WordPress plugin before 6.0.0.0's member-visibility setting.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
Unknown · ProfileGridpublic PoCs found — 1
cve_referencewpscan.com/vulnerability/701607f3-34b1-4f69-990b-c9ce56b58087/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.