Executive brief
A vulnerability in a WordPress plugin used for WooCommerce user profiles allows low-level users, such as subscribers, to install and activate additional software on the site without permission. This could lead to unauthorized changes in site functionality and potential security risks by introducing new plugins. The issue affects versions up to 3.4 and requires the attacker to have a basic account on the website.
Technical details
The ProfileGrid WooCommerce Integration plugin for WordPress (versions up to 3.4) contains a missing authorization vulnerability in the pg_install_profilegrid() AJAX handler. The handler, registered via wp_ajax_pg_install_profilegrid, fails to perform capability checks or nonce validation. This allows authenticated attackers with Subscriber-level permissions or higher to trigger the installation and activation of the ProfileGrid plugin from the WordPress repository. The vulnerability is classified as CWE-862 (Missing Authorization).
Affected products
- metagauss Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration up to, and including, 3.4
Timeline
- 2026-07-09: advisory: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/ecommerce-user-profiles-by-profilegrid/tags/3.4/admin/class-profilegrid-woocommerce-admin.php
- https://plugins.trac.wordpress.org/browser/ecommerce-user-profiles-by-profilegrid/tags/3.4/admin/class-profilegrid-woocommerce-admin.php
- https://plugins.trac.wordpress.org/browser/ecommerce-user-profiles-by-profilegrid/tags/3.4/includes/class-profilegrid-woocommerce.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3592677%40ecommerce-user-profiles-by-profilegrid&new=3592677%40ecommerce-user-profiles-by-profilegrid
- https://www.wordfence.com/threat-intel/vulnerabilities/id/4cce2842-bd8e-4a83-b83c-66aefe4df4b8?source=cve