ProfileGrid – User Profiles, Groups and Communities <= 5.9.9.6 - Unauthenticated Privilege Escalation via Password Reset
2026-07-08 00:00
Jakub HermanStrategic Overview
StatusPatched in 5.9.9.7
Affected PluginProfileGrid – User Profiles, Groups and Communities
Affected Version
<= 5.9.9.6CVSS9.8Critical
CVE
CVE-2026-57697Vulnerability Overview
The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.9.9.6. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.
Technical Analysis
REMEDIATION: Update to version 5.9.9.7, or a newer patched version --- IDENTIFIER: CWE-521 (Weak Password Requirements) The product does not require that users should have strong passwords.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C