CVE-2026-4609: Unauthorized Access in ProfileGrid
平台
wordpress
组件
profilegrid-user-profiles-groups-and-communities
修复版本
5.9.8.5
CVE-2026-4609 affects ProfileGrid, a WordPress plugin for user profiles, groups, and communities. This vulnerability allows authenticated attackers with Subscriber-level access or higher to bypass authorization checks and add users to any group, regardless of its access restrictions or payment status. The vulnerability impacts versions 0.0.0 through 5.9.8.4, and a fix is available in version 5.9.8.5.
检测此 CVE 是否影响你的项目
上传你的依赖文件,立即了解此CVE和其他CVE是否影响你。
影响与攻击场景翻译中…
The primary impact of CVE-2026-4609 is the potential for unauthorized access to closed and paid groups within ProfileGrid. An attacker, already logged in with a Subscriber account or higher, can leverage this vulnerability to add themselves or other registered users to these groups. This bypasses all authorization and payment mechanisms, granting access to content and features that should be restricted. This could lead to data breaches, exposure of sensitive information, and disruption of paid services. The ability to add arbitrary users to groups also opens the door for further malicious activity within those groups, such as spamming or phishing campaigns.
利用背景翻译中…
CVE-2026-4609 was published on May 13, 2026. Its severity is rated HIGH (CVSS 7.1). Currently, there are no publicly available exploits or active campaigns targeting this vulnerability. It is not listed on KEV or EPSS, indicating a low to medium probability of exploitation. Monitor security advisories and threat intelligence feeds for any updates.
威胁情报
漏洞利用状态
CVSS 向量
这些指标意味着什么?
- Attack Vector
- 网络 — 可通过互联网远程利用,无需物理或本地访问。攻击面最大。
- Attack Complexity
- 低 — 无需特殊条件,可以稳定地利用漏洞。
- Privileges Required
- 低 — 任何有效用户账户均可。
- User Interaction
- 无 — 攻击自动且无声,受害者无需任何操作。
- Scope
- 未改变 — 影响仅限于脆弱组件本身。
- Confidentiality
- 低 — 可访问部分数据。
- Integrity
- 高 — 攻击者可写入、修改或删除任何数据。
- Availability
- 无 — 无可用性影响。
受影响的软件
弱点分类 (CWE)
时间线
- 已保留
- 发布日期
- 修改日期
缓解措施和替代方案翻译中…
The recommended mitigation for CVE-2026-4609 is to immediately upgrade ProfileGrid to version 5.9.8.5 or later. If upgrading is not immediately feasible due to compatibility issues or breaking changes, consider implementing a temporary workaround by restricting group membership management to administrators only. Review user roles and permissions within ProfileGrid to ensure that only authorized personnel have the ability to manage group memberships. While a direct WAF rule is difficult to implement, monitor ProfileGrid logs for suspicious activity related to group membership changes and user additions.
修复方法
更新到 5.9.8.5 版本,或更新的补丁版本
常见问题翻译中…
What is CVE-2026-4609 — Unauthorized Access in ProfileGrid?
CVE-2026-4609 is a HIGH severity vulnerability in ProfileGrid WordPress plugin allowing authenticated users to bypass authorization and add users to any group, including paid ones, impacting versions 0.0.0–5.9.8.4.
Am I affected by CVE-2026-4609 in ProfileGrid?
If you are using ProfileGrid version 0.0.0 through 5.9.8.4 on your WordPress site, you are potentially affected by this vulnerability. Check your plugin version immediately.
How do I fix CVE-2026-4609 in ProfileGrid?
Upgrade ProfileGrid to version 5.9.8.5 or later to resolve the vulnerability. If immediate upgrade is not possible, restrict group membership management to administrators as a temporary workaround.
Is CVE-2026-4609 being actively exploited?
As of the current assessment, CVE-2026-4609 is not known to be actively exploited, but it remains a significant risk due to the ease of exploitation.
Where can I find the official ProfileGrid advisory for CVE-2026-4609?
Refer to the ProfileGrid website and WordPress plugin repository for the official advisory and update information regarding CVE-2026-4609.
检测此 CVE 是否影响你的项目
上传你的依赖文件,立即了解此CVE和其他CVE是否影响你。
立即扫描您的WordPress项目 — 无需账户
上传任何清单文件 (composer.lock, package-lock.json, WordPress 插件列表…) 或粘贴您的组件列表。您立即获得一份漏洞报告。上传文件只是开始:拥有账户后,您将获得持续监控、Slack/电子邮件警报、多项目和白标报告。
拖放您的依赖文件
composer.lock、package-lock.json、requirements.txt、Gemfile.lock、pubspec.lock、Dockerfile...