Junglewise Threat Intelligence

CVE-2026-57759: Metagauss ProfileGrid CSRF to account takeover

CVE-2026-57759 · Severity: high · CVSS 8.8 · Published 2026-07-02

Vendors: Metagauss.

Executive brief

ProfileGrid, a WordPress plugin used for managing user profiles and communities, contains a security flaw that could allow an attacker to take over user accounts. By tricking an authorized administrator or user into clicking a malicious link, an attacker can force the website to perform actions on the victim's behalf without their knowledge. This can lead to unauthorized changes to site settings or full account compromise.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Metagauss ProfileGrid plugin for WordPress (versions up to and including 5.9.9.7). The flaw stems from a lack of nonce validation or insufficient protection on sensitive actions, allowing unauthenticated attackers to craft malicious requests. If a logged-in administrative user interacts with a specially crafted link or page, the attacker can execute unauthorized actions under the victim's security context. According to the advisory, this specific CSRF can be leveraged to achieve account takeover. As of the publication date, no official patch has been confirmed.

Affected products

  • Metagauss ProfileGrid <= 5.9.9.7

Timeline

  • 2026-05-17: other: Reported by researcher dodoh4t
  • 2026-07-02: advisory: Published by Patchstack

References