分析待ちCVE-2026-4609

CVE-2026-4609: Unauthorized Access in ProfileGrid

プラットフォーム

wordpress

コンポーネント

profilegrid-user-profiles-groups-and-communities

修正版

5.9.8.5

CVE-2026-4609 affects ProfileGrid, a WordPress plugin for user profiles, groups, and communities. This vulnerability allows authenticated attackers with Subscriber-level access or higher to bypass authorization checks and add users to any group, regardless of its access restrictions or payment status. The vulnerability impacts versions 0.0.0 through 5.9.8.4, and a fix is available in version 5.9.8.5.

WordPress

このCVEがあなたのプロジェクトに影響するか確認

依存関係ファイルをアップロードすれば、このCVEや他のCVEがあなたに影響するか即座にわかります。

影響と攻撃シナリオ翻訳中…

The primary impact of CVE-2026-4609 is the potential for unauthorized access to closed and paid groups within ProfileGrid. An attacker, already logged in with a Subscriber account or higher, can leverage this vulnerability to add themselves or other registered users to these groups. This bypasses all authorization and payment mechanisms, granting access to content and features that should be restricted. This could lead to data breaches, exposure of sensitive information, and disruption of paid services. The ability to add arbitrary users to groups also opens the door for further malicious activity within those groups, such as spamming or phishing campaigns.

悪用の状況翻訳中…

CVE-2026-4609 was published on May 13, 2026. Its severity is rated HIGH (CVSS 7.1). Currently, there are no publicly available exploits or active campaigns targeting this vulnerability. It is not listed on KEV or EPSS, indicating a low to medium probability of exploitation. Monitor security advisories and threat intelligence feeds for any updates.

脅威インテリジェンス

エクスプロイト状況

概念実証不明
CISA KEVNO
インターネット露出

CVSS ベクトル

脅威インテリジェンス· CVSS 3.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N7.1HIGHAttack VectorNetwork攻撃者がターゲットに到達する方法Attack ComplexityLow悪用に必要な条件Privileges RequiredLow攻撃に必要な認証レベルUser InteractionNone被害者の操作が必要かどうかScopeUnchanged影響コンポーネント外への波及ConfidentialityLow機密データ漏洩のリスクIntegrityHigh不正データ改ざんのリスクAvailabilityNoneサービス障害のリスクnextguardhq.com · CVSS v3.1 基本スコア
これらのメトリクスの意味は?
Attack Vector
ネットワーク — インターネット経由でリモートから悪用可能。物理・ローカルアクセス不要。
Attack Complexity
低 — 特別な条件不要。安定して悪用可能。
Privileges Required
低 — 有効なユーザーアカウントがあれば十分。
User Interaction
なし — 自動かつ無音の攻撃。被害者は何もしない。
Scope
変化なし — 影響は脆弱なコンポーネントのみ。
Confidentiality
低 — 一部データへの部分的アクセス。
Integrity
高 — 任意のデータの書き込み・変更・削除が可能。
Availability
なし — 可用性への影響なし。

影響を受けるソフトウェア

コンポーネントprofilegrid-user-profiles-groups-and-communities
ベンダーwordfence
最小バージョン0.0.0
最大バージョン5.9.8.4
修正版5.9.8.5

弱点分類 (CWE)

タイムライン

  1. Reserved
  2. 公開日

緩和策と回避策翻訳中…

The recommended mitigation for CVE-2026-4609 is to immediately upgrade ProfileGrid to version 5.9.8.5 or later. If upgrading is not immediately feasible due to compatibility issues or breaking changes, consider implementing a temporary workaround by restricting group membership management to administrators only. Review user roles and permissions within ProfileGrid to ensure that only authorized personnel have the ability to manage group memberships. While a direct WAF rule is difficult to implement, monitor ProfileGrid logs for suspicious activity related to group membership changes and user additions.

修正方法

バージョン5.9.8.5、またはそれ以降の修正バージョンにアップデートしてください

よくある質問翻訳中…

What is CVE-2026-4609 — Unauthorized Access in ProfileGrid?

CVE-2026-4609 is a HIGH severity vulnerability in ProfileGrid WordPress plugin allowing authenticated users to bypass authorization and add users to any group, including paid ones, impacting versions 0.0.0–5.9.8.4.

Am I affected by CVE-2026-4609 in ProfileGrid?

If you are using ProfileGrid version 0.0.0 through 5.9.8.4 on your WordPress site, you are potentially affected by this vulnerability. Check your plugin version immediately.

How do I fix CVE-2026-4609 in ProfileGrid?

Upgrade ProfileGrid to version 5.9.8.5 or later to resolve the vulnerability. If immediate upgrade is not possible, restrict group membership management to administrators as a temporary workaround.

Is CVE-2026-4609 being actively exploited?

As of the current assessment, CVE-2026-4609 is not known to be actively exploited, but it remains a significant risk due to the ease of exploitation.

Where can I find the official ProfileGrid advisory for CVE-2026-4609?

Refer to the ProfileGrid website and WordPress plugin repository for the official advisory and update information regarding CVE-2026-4609.

あなたのプロジェクトは影響を受けていますか?

依存関係ファイルをアップロードすれば、このCVEや他のCVEがあなたに影響するか即座にわかります。

WordPress

このCVEがあなたのプロジェクトに影響するか確認

依存関係ファイルをアップロードすれば、このCVEや他のCVEがあなたに影響するか即座にわかります。

scanZone.liveBadgescanZone.eyebrow

WordPressプロジェクトを今すぐスキャン — アカウント不要

Upload any manifest (composer.lock, package-lock.json, WordPress plugin list…) or paste your component list. You get a vulnerability report instantly. Uploading a file is just the start: with an account you get continuous monitoring, Slack/email alerts, multi-project and white-label reports.

手動スキャンSlack/メールアラートContinuous monitoringホワイトラベルレポート

依存関係ファイルをドラッグ&ドロップ

composer.lock、package-lock.json、requirements.txt、Gemfile.lock、pubspec.lock、Dockerfile...