Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-44071 | The ProfileGrid plugin for WordPress is vulnerable to unauthorized decryption of private information in versions up to, and including, 5.5.0. This is due to the passphrase and iv being hardcoded in the 'pm_encrypt_decrypt_pass' function and used across all sites running the plugin. This makes it possible for authenticated attackers, with administrator-level permissions or above to decrypt and view users' passwords. If combined with another vulnerability, this can potentially grant lower-privileged users access to users' passwords. |
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | ProfileGrid <= 5.5.0 - Hardcoded Encryption Key | |
| Weaknesses | CWE-321 |
Wed, 05 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:59:24.379Z
Reserved: 2023-06-26T12:32:34.057Z
Link: CVE-2023-3404
Updated: 2024-08-02T06:55:03.396Z
Status : Modified
Published: 2023-08-31T06:15:09.860
Modified: 2026-04-08T18:18:09.700
Link: CVE-2023-3404
No data.
OpenCVE Enrichment
No data.
EUVD