Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total22
Critical1
High3
Medium18
Reset
Showing 21-22 of 22 records
Threat Entry Updated 2025-02-10

CVE-2024-3606 - Groups And Communities Plugin

The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the pm_upload_cover_image function in all versions up to, and including, 5.8.3. This makes it possible for authenticated attackers, with subscriber access or higher, to delete attachments.

PLUGIN Groups And Communities

CVE-2024-3606

MEDIUM CVSS 4.3 2024-05-02
Threat Entry Updated 2024-11-21

CVE-2022-0233 - Groups And Communities Plugin

The ProfileGrid – User Profiles, Memberships, Groups and Communities WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the pm_user_avatar and pm_cover_image parameters found in the ~/admin/class-profile-magic-admin.php file which allows attackers with authenticated user access, such as subscribers, to inject arbitrary web scripts into their profile, in versions up to and including 1.2.7.

PLUGIN Groups And Communities

CVE-2022-0233

MEDIUM CVSS 6.4 2022-01-18
Scroll to top