| CVE-2024-49619 | WordPress Social Link Groups plugin <= 1.1.0 - SQL Injection vulnerability | acespritech | Social Link Groups | High | 8.5 | 2024-10-20 09:09:20 | Deep Dive |
| CVE-2024-48032 | WordPress Featured Posts with Multiple Custom Groups (FPMCG) plugin <= 4.0 - Reflected Cross Site Scripting (XSS) vulnerability | sumitsurai | Featured Posts with Multiple Custom Groups (FPMCG) | High | 7.1 | 2024-10-17 12:22:07 | Deep Dive |
| CVE-2024-48031 | WordPress Featured Posts with Multiple Custom Groups (FPMCG) plugin <= 4.0 - Cross-Site Request Forgery (CSRF) vulnerability | sumitsurai | Featured Posts with Multiple Custom Groups (FPMCG) | Medium | 6.5 | 2024-10-17 12:15:53 | Deep Dive |
| CVE-2022-4974 | Freemius SDK <= 2.4.2 - Missing Authorization Checks | dashlabsltd | YASR – Yet Another Star Rating Plugin for WordPress | Medium | 6.3 | 2024-10-16 06:43:30 | Deep Dive |
| CVE-2024-8861 | ProfileGrid – User Profiles, Groups and Communities <= 5.9.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting | metagauss | ProfileGrid – User Profiles, Groups and Communities | Medium | 6.4 | 2024-09-26 07:34:37 | Deep Dive |
| CVE-2024-43237 | WordPress Tag Groups plugin <= 2.0.3 - Sensitive Data Exposure vulnerability | Steve Burge | WordPress Tag Cloud Plugin – Tag Groups | Medium | 5.3 | 2024-09-25 14:49:00 | Deep Dive |
| CVE-2024-8350 | Uncanny Groups for LearnDash <= 6.1.0.1 - Missing Authorization to Authenticated (Group Leader+) User Group Add | Uncanny Owl | Uncanny Groups for LearnDash | Low | 2.7 | 2024-09-25 02:32:27 | Deep Dive |
| CVE-2024-8349 | Uncanny Groups for LearnDash <= 6.1.0.1 - Authenticated (Group Leader+) Privilege Escalation | Uncanny Owl | Uncanny Groups for LearnDash | High | 7.2 | 2024-09-25 02:32:26 | Deep Dive |
| CVE-2024-6410 | ProfileGrid <= 5.8.9 - Authenticated (Subscriber+) Insecure Direct Object Reference | metagauss | ProfileGrid – User Profiles, Groups and Communities | Medium | 4.3 | 2024-07-10 04:31:31 | Deep Dive |
| CVE-2024-6411 | ProfileGrid – User Profiles, Groups and Communities <= 5.8.9 - Authenticated (Subscriber+) Authorization Bypass to Privilege Escalation | metagauss | ProfileGrid – User Profiles, Groups and Communities | High | 8.8 | 2024-07-10 04:31:30 | Deep Dive |
| CVE-2024-5453 | ProfileGrid <= 5.8.6 - Missing Authorization | metagauss | ProfileGrid – User Profiles, Groups and Communities | Medium | 4.3 | 2024-06-05 07:34:56 | Deep Dive |
| CVE-2024-3606 | ProfileGrid – User Profiles, Memberships, Groups and Communities <= 5.8.3 - Missing Authorization | metagauss | ProfileGrid – User Profiles, Groups and Communities | Medium | 4.3 | 2024-05-02 16:52:34 | Deep Dive |
| CVE-2024-1108 | Plugin Groups <= 2.0.6 - Missing Authorization to Unauthenticated Denial of Service | desertsnowman | Plugin Groups | Medium | 6.5 | 2024-02-21 03:03:24 | Deep Dive |
| CVE-2022-36352 | WordPress ProfileGrid Plugin <= 5.0.3 is vulnerable to Broken Access Control | Profilegrid | ProfileGrid – User Profiles, Memberships, Groups and Communities | Medium | 6.3 | 2024-01-08 21:50:11 | Deep Dive |
| CVE-2023-47644 | WordPress ProfileGrid Plugin <= 5.6.6 is vulnerable to Cross Site Request Forgery (CSRF) | profilegrid | ProfileGrid – User Profiles, Memberships, Groups and Communities | Medium | 5.4 | 2023-11-18 21:31:40 | Deep Dive |
| CVE-2023-3404 | ProfileGrid <= 5.5.0 - Hardcoded Encryption Key | metagauss | ProfileGrid – User Profiles, Groups and Communities | Medium | 4.9 | 2023-08-31 05:33:10 | Deep Dive |
| CVE-2023-3714 | ProfileGrid <= 5.5.2 - Missing Authorization to Arbitrary Group Option Modification and Privilege Escalation | metagauss | ProfileGrid – User Profiles, Groups and Communities | High | 7.5 | 2023-07-18 02:39:26 | Deep Dive |
| CVE-2023-3403 | ProfileGrid <= 5.5.1 - Missing Authorization to User Import | metagauss | ProfileGrid – User Profiles, Groups and Communities | Medium | 5.4 | 2023-07-18 02:39:26 | Deep Dive |
| CVE-2023-3713 | ProfileGrid <= 5.5.1 - Authenticated (Subscriber+) Arbitrary Option Update | metagauss | ProfileGrid – User Profiles, Groups and Communities | High | 8.8 | 2023-07-18 02:39:25 | Deep Dive |
| CVE-2022-3578 | ProfileGrid < 5.1.1 - Reflected Cross-Site Scripting | Unknown | ProfileGrid – User Profiles, Memberships, Groups and Communities | 中危 | - | 2022-11-14 00:00:00 | Deep Dive |