• Resolved groggy72

    (@groggy72)


    WordPress ProfileGrid plugin <= 5.9.9.7 – CSRF to Account Takeover vulnerability

    Priority is low but thought I would flag it

Viewing 4 replies - 1 through 4 (of 4 total)
  • Plugin Support vincentpg

    (@vincentpg)

    Hi,

    Thank you for bringing this to our attention.

    We appreciate you taking the time to report this issue. We will review the findings internally to verify the reported behavior and assess the impact.

    If the issue is confirmed, we will include the necessary fix in an upcoming ProfileGrid release.

    Thank you again for helping us improve the security of ProfileGrid.

    Thread Starter groggy72

    (@groggy72)

    Thanks for looking into this. I know you patched it but it’s still viewed as vulnerable

    https://imgur.com/a/4Mj6BKp

    Plugin Support vincentpg

    (@vincentpg)

    Hi,

    Thank you for following up and for sharing the screenshot.

    This issue has already been addressed by our team and the fix was included in ProfileGrid v5.9.9.9.

    Could you please verify the issue against the latest version and let us know if the vulnerability is still reproducible? If you have any reproduction steps or additional details for v5.9.9.9, we would be happy to investigate further.

    Thank you again for reporting this and helping us improve the security of ProfileGrid.

    • This reply was modified 3 days, 22 hours ago by vincentpg.
    Thread Starter groggy72

    (@groggy72)

    Thank you for looking into this but it looks like it’s still an issue

    View post on imgur.com

Viewing 4 replies - 1 through 4 (of 4 total)

You must be logged in to reply to this topic.