ProfileGrid – User Profiles, Groups and Communities <= 2.8.5 - Authenticated Code ExecutionSign up to our free email alerts service for instant vulnerability notifications!
The plugin ProfileGrid – User Profiles, Groups and Communities versions prior to 2.8.6 is vulnerable to Arbitrary Code Execution. An authenticated user with a role as low as Subscriber can execute arbitrary PHP code on websites using the plugin.
|Proof of Concept||
fixed in version 2.8.6
|OWASP Top 10||A1: Injection|
|Submitter||Karim El Ouerghemmi|
|Publicly Published||2018-05-18 (6 days ago)|
|Added||2018-05-18 (5 days ago)|
|Last Updated||2018-05-18 (5 days ago)|
Copyright & License
|Copyright||All data and resources contained within this page and this web site is Copyright © The WPScan Team.|
|License||Some of this data may be used for non-commercial purposes, however, any potential commercial usage of this data will require a license. If you would like to inquire about a commercial license please contact us.|