Executive brief
A vulnerability in the ProfileGrid WordPress plugin allows registered users to bypass security controls and join any group on the site. This includes the ability to gain unauthorized access to private or premium paid groups without paying the required fees. This could lead to loss of revenue and unauthorized access to restricted community content.
Technical details
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to missing authorization (CWE-862) in the pm_invite_user function. The vulnerability exists in all versions up to and including 5.9.8.4 because the function lacks a proper capability check. An authenticated attacker with at least Subscriber-level permissions can exploit this to add themselves or other registered users to any group. This bypasses authorization logic and payment gateways intended for closed or premium groups. A patch has been released in subsequent versions.
Affected products
- ProfileGrid ProfileGrid – User Profiles, Groups and Communities Up to, and including, 5.9.8.4
Timeline
- 2026-05-13: advisory: NVD published the vulnerability details.
References
- https://plugins.trac.wordpress.org/browser/profilegrid-user-profiles-groups-and-communities/trunk/public/class-profile-magic-public.php
- https://plugins.trac.wordpress.org/browser/profilegrid-user-profiles-groups-and-communities/trunk/public/class-profile-magic-public.php
- https://plugins.trac.wordpress.org/changeset/3491679/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/c3678b4d-0cd0-4873-8cf3-90c557931f4c?source=cve