Export limit exceeded: 370023 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (3 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-12688 | 2 Profilegrid, Wordpress | 2 Profilegrid, Wordpress | 2026-07-24 | N/A |
| The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group membership, allowing unauthenticated attackers to forge a payment notification and mark any user as a paid member of any group without any payment being made. | ||||
| CVE-2026-12689 | 2 Profilegrid, Wordpress | 2 Profilegrid, Wordpress | 2026-07-24 | N/A |
| The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions, allowing authenticated users with Subscriber-level access and above to soft-delete, tamper with the metadata of, and mark as read other users' private message threads. | ||||
| CVE-2026-12690 | 2 Profilegrid, Wordpress | 2 Profilegrid, Wordpress | 2026-07-24 | N/A |
| The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its license management actions, relying only on a nonce that is exposed to any logged-in user, allowing authenticated users with Subscriber-level access and above to overwrite the site's premium license settings. | ||||
Page 1 of 1.