Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-4859 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.4.2 via the pm_messenger_show_messages function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read private conversations of other users. |
Mon, 24 Feb 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Metagauss
Metagauss profilegrid |
|
| CPEs | cpe:2.3:a:metagauss:profilegrid:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Metagauss
Metagauss profilegrid |
Tue, 18 Feb 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.4.2 via the pm_messenger_show_messages function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read private conversations of other users. | |
| Title | ProfileGrid – User Profiles, Groups and Communities <= 5.9.4.2 - Insecure Direct Object Reference to Authenticated (Subscriber+) Private Messages Disclosure | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:20:12.064Z
Reserved: 2025-01-27T00:01:03.457Z
Link: CVE-2024-13740
No data.
Status : Analyzed
Published: 2025-02-18T03:15:10.273
Modified: 2025-02-24T12:41:27.353
Link: CVE-2024-13740
No data.
OpenCVE Enrichment
No data.
EUVD