The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 5.9.4.2 via the pm_upload_image function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to download and view images, as well as validating if a non-image file exists, both on local or remote hosts.
Metrics
Affected Vendors & Products
References
History
Mon, 24 Feb 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Metagauss
Metagauss profilegrid |
|
| CPEs | cpe:2.3:a:metagauss:profilegrid:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Metagauss
Metagauss profilegrid |
Tue, 18 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Feb 2025 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 5.9.4.2 via the pm_upload_image function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to download and view images, as well as validating if a non-image file exists, both on local or remote hosts. | |
| Title | ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.2 - Authenticated (Subscriber+) Limited Server-Side Request Forgery | |
| Weaknesses | CWE-918 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-02-18T01:44:00.964Z
Updated: 2025-02-18T19:28:54.756Z
Reserved: 2025-01-27T00:29:42.976Z
Link: CVE-2024-13741
Updated: 2025-02-18T15:08:48.455Z
Status : Analyzed
Published: 2025-02-18T02:15:13.047
Modified: 2025-02-24T12:40:05.483
Link: CVE-2024-13741
No data.