A critical vulnerability was found in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities. This affects an unknown part of the component ProfileGrid, allowing for authentication bypass using an alternate path or channel. The exploit has been disclosed to the public and may be used. The identifier VDB-273254 was assigned to this vulnerability. Users of Metagauss ProfileGrid profilegrid-u [truncated]
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pm_author_message' parameter in the pm_send_message_to_author function in all versions up to, and including, 5.9.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to injec [truncated]
CVE-2026-49764 is a critical vulnerability with a CVSS score of 9.8. It affects RegistrationMagic plugin versions <= 6.0.8.6 and allows unauthenticated broken authentication. The vulnerability was published on [cvePublishedAt] and last modified on [cveModifiedAt].