Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-1408

Опубликовано: 22 мар. 2025
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_decline_join_group_request and pm_approve_join_group_request functions in all versions up to, and including, 5.9.4.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to approve or decline join group requests which is normally should be available to administrators only.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:metagauss:profilegrid:*:*:*:*:*:wordpress:*:*
Версия до 5.9.4.5 (исключая)

EPSS

Процентиль: 30%
0.00113
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862
CWE-862

Связанные уязвимости

CVSS3: 4.3
github
11 месяцев назад

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pm_decline_join_group_request and pm_approve_join_group_request functions in all versions up to, and including, 5.9.4.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to approve or decline join group requests which is normally should be available to administrators only.

EPSS

Процентиль: 30%
0.00113
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862
CWE-862