CVE-2026-4609: Unauthorized Access in ProfileGrid
Plataforma
wordpress
Componente
profilegrid-user-profiles-groups-and-communities
Corrigido em
5.9.8.5
CVE-2026-4609 affects ProfileGrid, a WordPress plugin for user profiles, groups, and communities. This vulnerability allows authenticated attackers with Subscriber-level access or higher to bypass authorization checks and add users to any group, regardless of its access restrictions or payment status. The vulnerability impacts versions 0.0.0 through 5.9.8.4, and a fix is available in version 5.9.8.5.
Detecte esta CVE no seu projeto
Envie seu arquivo de dependências e descubra na hora se esta e outras CVEs te atingem.
Impacto e Cenários de Ataquetraduzindo…
The primary impact of CVE-2026-4609 is the potential for unauthorized access to closed and paid groups within ProfileGrid. An attacker, already logged in with a Subscriber account or higher, can leverage this vulnerability to add themselves or other registered users to these groups. This bypasses all authorization and payment mechanisms, granting access to content and features that should be restricted. This could lead to data breaches, exposure of sensitive information, and disruption of paid services. The ability to add arbitrary users to groups also opens the door for further malicious activity within those groups, such as spamming or phishing campaigns.
Contexto de Exploraçãotraduzindo…
CVE-2026-4609 was published on May 13, 2026. Its severity is rated HIGH (CVSS 7.1). Currently, there are no publicly available exploits or active campaigns targeting this vulnerability. It is not listed on KEV or EPSS, indicating a low to medium probability of exploitation. Monitor security advisories and threat intelligence feeds for any updates.
Inteligência de Ameaças
Status do Exploit
Vetor CVSS
O que significam essas métricas?
- Attack Vector
- Rede — explorável remotamente pela internet. Sem acesso físico ou local necessário.
- Attack Complexity
- Baixa — sem condições especiais. O atacante pode explorar de forma confiável.
- Privileges Required
- Baixo — qualquer conta de usuário válida é suficiente.
- User Interaction
- Nenhuma — ataque automático e silencioso. A vítima não faz nada.
- Scope
- Inalterado — impacto limitado ao componente vulnerável.
- Confidentiality
- Baixo — acesso parcial ou indireto a alguns dados.
- Integrity
- Alto — o atacante pode escrever, modificar ou excluir qualquer dado.
- Availability
- Nenhum — sem impacto na disponibilidade.
Software Afetado
Classificação de Fraqueza (CWE)
Linha do tempo
- Reserved
- Publicada
Mitigação e Soluções Alternativastraduzindo…
The recommended mitigation for CVE-2026-4609 is to immediately upgrade ProfileGrid to version 5.9.8.5 or later. If upgrading is not immediately feasible due to compatibility issues or breaking changes, consider implementing a temporary workaround by restricting group membership management to administrators only. Review user roles and permissions within ProfileGrid to ensure that only authorized personnel have the ability to manage group memberships. While a direct WAF rule is difficult to implement, monitor ProfileGrid logs for suspicious activity related to group membership changes and user additions.
Como corrigir
Atualize para a versão 5.9.8.5, ou uma versão corrigida mais recente
Perguntas frequentestraduzindo…
What is CVE-2026-4609 — Unauthorized Access in ProfileGrid?
CVE-2026-4609 is a HIGH severity vulnerability in ProfileGrid WordPress plugin allowing authenticated users to bypass authorization and add users to any group, including paid ones, impacting versions 0.0.0–5.9.8.4.
Am I affected by CVE-2026-4609 in ProfileGrid?
If you are using ProfileGrid version 0.0.0 through 5.9.8.4 on your WordPress site, you are potentially affected by this vulnerability. Check your plugin version immediately.
How do I fix CVE-2026-4609 in ProfileGrid?
Upgrade ProfileGrid to version 5.9.8.5 or later to resolve the vulnerability. If immediate upgrade is not possible, restrict group membership management to administrators as a temporary workaround.
Is CVE-2026-4609 being actively exploited?
As of the current assessment, CVE-2026-4609 is not known to be actively exploited, but it remains a significant risk due to the ease of exploitation.
Where can I find the official ProfileGrid advisory for CVE-2026-4609?
Refer to the ProfileGrid website and WordPress plugin repository for the official advisory and update information regarding CVE-2026-4609.
Seu projeto está afetado?
Envie seu arquivo de dependências e descubra na hora se esta e outras CVEs te atingem.
Detecte esta CVE no seu projeto
Envie seu arquivo de dependências e descubra na hora se esta e outras CVEs te atingem.
Escaneie seu projeto WordPress agora — sem conta
Faça upload de qualquer manifesto (composer.lock, package-lock.json, lista de plugins WordPress…) ou cole sua lista de componentes. Receba um relatório de vulnerabilidades instantaneamente. Fazer upload de um arquivo é só o começo: com uma conta, você obtém monitoramento contínuo, alertas por Slack/email, relatórios multiprojeto e white-label.
Arraste e solte seu arquivo de dependências
composer.lock, package-lock.json, requirements.txt, Gemfile.lock, pubspec.lock, Dockerfile...