The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list, allowing any unauthenticated visitor to disclose the members and their identifiers of any group, including private or closed ones, bypassing the ProfileGrid WordPress plugin's member-visibility setting. This vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity [truncated]
The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests. This issue allows any authenticated user, including Subscribers, to disclose the names and request dates of users awaiting approval to join any group, including private ones. Authenticated users of WordPress sites with ProfileGrid plugin installed should be aware of pot [truncated]