Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

ProfileGrid – User Profiles, Groups and Communities Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 59 vulnerability records associated with ProfileGrid – User Profiles, Groups and Communities, published between 2018 and 2026.

Dataset last synchronized: 2026-08-02 09:41:47 UTC

At a glance

Security Snapshot

59Total records
4Critical
8High
46Medium
0Low
1Informational
58Patched records
1Currently marked unpatched
2018-05-18First disclosure
2026-07-08Latest disclosure
59 of 59CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
201811 records
202244 records
202377 records
20241717 records
20251515 records
20261515 records

Severity Breakdown

SeverityRecordsShare
Critical46.8%
High813.6%
Medium4678%
Informational11.7%

Vulnerability-Type Breakdown

Missing Authorization

27 records45.8%

First: 2022. Latest: 2026.

SQL Injection

9 records15.3%

First: 2024. Latest: 2026.

Other

7 records11.9%

First: 2018. Latest: 2025.

Cross-Site Scripting

7 records11.9%

First: 2022. Latest: 2026.

CSRF

5 records8.5%

First: 2023. Latest: 2026.

Privilege Escalation

3 records5.1%

First: 2024. Latest: 2026.

Information Disclosure

1 record1.7%

First: 2025. Latest: 2025.

Patch Status

Patched
58
Currently marked unpatched
1
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 5.9.9.7
  • 5.9.9.6
  • 5.9.9.3
  • 5.9.8.5
  • 5.9.8.2
  • 5.9.8.3
  • 5.9.7.3
  • 5.9.5.8
  • 5.9.5.4
  • 5.9.5.5
  • 5.9.5.3
  • 5.9.5.2
  • 5.9.5.1
  • 5.9.4.9
  • 5.9.4.6
  • 5.9.4.5
  • 5.9.4.8
  • 5.9.4.4
  • 5.9.4.3
  • 5.9.3.7
  • 5.9.3.1
  • 5.9.3.3
  • 5.9.0
  • 5.8.8
  • 5.8.7
  • 5.7.2
  • 5.8.3
  • 5.8.0
  • 5.8.4
  • 5.7.9
  • 5.7.7
  • 5.7.3
  • 5.6.7
  • 5.5.3
  • 5.5.1
  • 5.5.2
  • 5.3.1
  • 5.1.8
  • 5.0.4
  • 5.1.1
  • 4.7.7
  • 2.8.6

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-5.9.9.6ProfileGrid – User Profiles, Groups and Communities <= 5.9.9.6 - Unauthenticated Privilege Escalation via Password ResetJuly 8, 20265.9.9.7Critical
*-5.9.9.6ProfileGrid <= 5.9.9.6 - Unauthenticated Payment BypassJuly 3, 20265.9.9.7Medium
*-5.9.9.6ProfileGrid <= 5.9.9.6 - Missing AuthorizationJuly 3, 20265.9.9.7Medium
*-5.9.9.6ProfileGrid <= 5.9.9.6 - Missing AuthorizationJuly 3, 20265.9.9.7Medium
*-5.9.9.8ProfileGrid – User Profiles, Groups and Communities <= 5.9.9.8 - Cross-Site Request ForgeryJuly 2, 2026Not suppliedMedium
*-5.9.9.5ProfileGrid - User Profiles, Groups and Communities <= 5.9.9.5 - Unauthenticated Privilege Escalation via Email OverwriteJune 29, 20265.9.9.6Critical
*-5.9.9.2ProfileGrid <= 5.9.9.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Message ContentJune 22, 20265.9.9.3Medium
*-5.9.8.4ProfileGrid <= 5.9.8.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Group JoiningMay 12, 20265.9.8.5High
*-5.9.8.4ProfileGrid <= 5.9.8.4 - Missing Authorization to Authenticated (Subscriber+) Group Settings ModificationMay 12, 20265.9.8.5Medium
*-5.9.8.4ProfileGrid <= 5.9.8.4 - Authenticated (Subscriber+) SQL Injection via 'rid' ParameterMay 12, 20265.9.8.5Medium
*-5.9.8.1ProfileGrid – User Profiles, Groups and Communities <= 5.9.8.1 - Authenticated (Subscriber+) Stored Cross-Site ScriptingMarch 23, 20265.9.8.2Medium
*-5.9.8.1ProfileGrid <= 5.9.8.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Message DeletionMarch 6, 20265.9.8.2Medium
*-5.9.8.2ProfileGrid <= 5.9.8.2 - Cross-Site Request Forgery to Group Membership Request Approval/DenialMarch 6, 20265.9.8.3Medium
*-5.9.7.2ProfileGrid <= 5.9.7.2 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Profile and Cover Image ModificationFebruary 4, 20265.9.7.3Medium
*-5.9.7.2ProfileGrid – User Profiles, Groups and Communities <= 5.9.7.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User SuspensionFebruary 4, 20265.9.7.3Medium
*-5.9.5.7ProfileGrid – User Profiles, Groups and Communities <= 5.9.5.7 - Reflected Cross-Site ScriptingSeptember 1, 20255.9.5.8Medium
*-5.9.5.3ProfileGrid <= 5.9.5.3 - Authenticated (Subscriber+) SQL InjectionJuly 24, 20255.9.5.4Medium
*-5.9.5.4ProfileGrid – User Profiles, Groups and Communities <= 5.9.5.4 - Reflected Cross-Site Scripting via 'pm_get_messenger_notification' functionJuly 15, 20255.9.5.5Medium
*-5.9.5.2ProfileGrid <= 5.9.5.2 - Authenticated (Subscriber+) SQL InjectionJuly 10, 20255.9.5.3Medium
*-5.9.5.2ProfileGrid <= 5.9.5.2 - Authenticated (Subscriber+) Full Path DisclosureJune 19, 20255.9.5.3Medium
*-5.9.5.2ProfileGrid <= 5.9.5.2 - Authenticated (Subscriber+) Server-Side Request ForgeryJune 12, 20255.9.5.3Medium
*-5.9.5.1ProfileGrid <= 5.9.5.1 - Missing AuthorizationMay 16, 20255.9.5.2Medium
*-5.9.5.0ProfileGrid <= 5.9.5.0 - Authenticated (Subscriber+) SQL InjectionMay 12, 20255.9.5.1Medium
*-5.9.4.8ProfileGrid <= 5.9.4.8 - Authenticated (Subscriber+) SQL InjectionApril 17, 20255.9.4.9Medium
*-5.9.4.5ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.5 - Authenticated (Subscriber+) PHP Object InjectionMarch 21, 20255.9.4.6High

Selected source records

Latest Records

CriticalCVE-2026-57697

ProfileGrid – User Profiles, Groups and Communities <= 5.9.9.6 - Unauthenticated Privilege Escalation via Password Reset

Published: July 8, 2026

Affected versions
*-5.9.9.6
Patched versions
5.9.9.7
Original Wordfence record
MediumCVE-2026-12689

ProfileGrid <= 5.9.9.6 - Missing Authorization

Published: July 3, 2026

Affected versions
*-5.9.9.6
Patched versions
5.9.9.7
Original Wordfence record
MediumCVE-2026-12690

ProfileGrid <= 5.9.9.6 - Missing Authorization

Published: July 3, 2026

Affected versions
*-5.9.9.6
Patched versions
5.9.9.7
Original Wordfence record
MediumCVE-2026-12688

ProfileGrid <= 5.9.9.6 - Unauthenticated Payment Bypass

Published: July 3, 2026

Affected versions
*-5.9.9.6
Patched versions
5.9.9.7
Original Wordfence record
MediumCVE-2026-57759

ProfileGrid – User Profiles, Groups and Communities <= 5.9.9.8 - Cross-Site Request Forgery

Published: July 2, 2026

Affected versions
*-5.9.9.8
Patched versions
Not supplied
Original Wordfence record
CriticalCVE-2026-12073

ProfileGrid - User Profiles, Groups and Communities <= 5.9.9.5 - Unauthenticated Privilege Escalation via Email Overwrite

Published: June 29, 2026

Affected versions
*-5.9.9.5
Patched versions
5.9.9.6
Original Wordfence record
MediumCVE-2026-4610

ProfileGrid <= 5.9.9.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Message Content

Published: June 22, 2026

Affected versions
*-5.9.9.2
Patched versions
5.9.9.3
Original Wordfence record
MediumCVE-2026-4608

ProfileGrid <= 5.9.8.4 - Authenticated (Subscriber+) SQL Injection via 'rid' Parameter

Published: May 12, 2026

Affected versions
*-5.9.8.4
Patched versions
5.9.8.5
Original Wordfence record

Highest-Severity Records

CriticalCVE-2024-30490

ProfileGrid <= 5.7.8 - Unauthenticated SQL Injection

Published: March 28, 2024

Affected versions
*-5.7.8
Patched versions
5.7.9
Original Wordfence record
CriticalCVE-2024-30491

ProfileGrid <= 5.7.8 - Authenticated (Subscriber+) SQL Injection

Published: March 28, 2024

Affected versions
*-5.7.8
Patched versions
5.7.9
Original Wordfence record
CriticalCVE-2026-12073

ProfileGrid - User Profiles, Groups and Communities <= 5.9.9.5 - Unauthenticated Privilege Escalation via Email Overwrite

Published: June 29, 2026

Affected versions
*-5.9.9.5
Patched versions
5.9.9.6
Original Wordfence record
CriticalCVE-2026-57697

ProfileGrid – User Profiles, Groups and Communities <= 5.9.9.6 - Unauthenticated Privilege Escalation via Password Reset

Published: July 8, 2026

Affected versions
*-5.9.9.6
Patched versions
5.9.9.7
Original Wordfence record
HighCVE-2025-26999

ProfileGrid <= 5.9.4.3 - Authenticated (Subscriber+) PHP Object Injection

Published: February 23, 2025

Affected versions
*-5.9.4.3
Patched versions
5.9.4.4
Original Wordfence record
HighCVE-2024-6411

ProfileGrid – User Profiles, Groups and Communities <= 5.8.9 - Authenticated (Subscriber+) Authorization Bypass to Privilege Escalation

Published: July 9, 2024

Affected versions
*-5.8.9
Patched versions
5.9.0
Original Wordfence record
HighCVE-2023-3713

ProfileGrid <= 5.5.1 - Authenticated (Subscriber+) Arbitrary Option Update

Published: July 17, 2023

Affected versions
*-5.5.1
Patched versions
5.5.2
Original Wordfence record
HighCVE-2023-0940

ProfileGrid <= 5.3.0 - Missing Authorization to Arbitrary Password Reset

Published: February 27, 2023

Affected versions
*-5.3.0
Patched versions
5.3.1
Original Wordfence record

Currently Marked Unpatched Records

MediumCVE-2026-57759

ProfileGrid – User Profiles, Groups and Communities <= 5.9.9.8 - Cross-Site Request Forgery

Published: July 2, 2026

Affected versions
*-5.9.9.8
Patched versions
Not supplied
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory