The ProfileGrid – User Profiles, Memberships, Groups and Communities plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the pm_upload_cover_image function in all versions up to, and including, 5.8.3. This makes it possible for authenticated attackers, with subscriber access or higher, to delete attachments.
History

Mon, 10 Feb 2025 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Metagauss
Metagauss profilegrid
Weaknesses CWE-862
CPEs cpe:2.3:a:metagauss:profilegrid:*:*:*:*:*:wordpress:*:*
Vendors & Products Metagauss
Metagauss profilegrid

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-08-01T20:12:07.965Z

Reserved: 2024-04-10T17:20:19.725Z

Link: CVE-2024-3606

cve-icon Vulnrichment

Updated: 2024-08-01T20:12:07.965Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-02T17:15:28.067

Modified: 2025-02-10T22:32:03.097

Link: CVE-2024-3606

cve-icon Redhat

No data.