Pricing
Solutions
WordPress security
Instantly fix and mitigate vulnerabilities
Plugin auditing
Paid auditing for WordPress vendors
Managed VDP
Start a security program for your plugins
Bug Bounty
Join the community and earn bounties
Enterprise API
At scale monitoring and vPatching for hosts
Vulnerability database
The latest WordPress security intelligence
Login
Start trial
ProfileGrid
Metagauss
Developer
5.9.6.5
Latest version
6,000
Installations
7 days ago
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
43 fixed
23 Mitigation rules
Reflected Cross Site Scripting (XSS) vulnerability
<= 5.9.5.7
Sep 1, 2025
SQL Injection Vulnerability
<= 5.9.5.3
Jul 24, 2025
Reflected Cross-Site Scripting via 'pm_get_messenger_notification' function vulnerability
<= 5.9.5.4
Jul 16, 2025
SQL Injection Vulnerability
<= 5.9.5.2
Jul 10, 2025
Full Path Disclosure (FPD) Vulnerability
<= 5.9.5.2
Jun 19, 2025
Server Side Request Forgery (SSRF) Vulnerability
<= 5.9.5.2
Jun 12, 2025
Broken Access Control Vulnerability
<= 5.9.5.1
May 16, 2025
SQL Injection Vulnerability
<= 5.9.5.0
May 12, 2025
SQL Injection Vulnerability
<= 5.9.4.8
Apr 17, 2025
Authenticated (Subscriber+) SQL Injection vulnerability
<= 5.9.4.7
Mar 21, 2025
PHP Object Injection vulnerability
<= 5.9.4.3
Feb 23, 2025
Insecure Direct Object Reference to Authenticated (Subscriber+) Private Messages Disclosure vulnerability
<= 5.9.4.2
Feb 17, 2025
Authenticated (Subscriber+) Limited Server-Side Request Forgery vulnerability
<= 5.9.4.2
Feb 17, 2025
Missing Authorization to Authenticated (Subscriber+) Arbitrary User Meta Deletion vulnerability
<= 5.9.3.6
Nov 19, 2024
Cross Site Request Forgery (CSRF) vulnerability
<= 5.9.3
Oct 14, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 5.9.3.2
Sep 26, 2024
Authenticated (Subscriber+) Insecure Direct Object Reference vulnerability
<= 5.8.9
Jul 10, 2024
Authenticated Privilege Escalation vulnerability
<= 5.8.9
Jul 9, 2024
Broken Access Control vulnerability
<= 5.8.7
Jul 1, 2024
Missing Authorization vulnerability
<= 5.8.6
Jun 5, 2024
Insecure Direct Object Reference (IDOR) vulnerability
<= 5.7.9
Apr 22, 2024
Group Members Limit Bypass vulnerability
<= 5.8.2
Apr 22, 2024
Insecure Direct Object References (IDOR) vulnerability
<= 5.7.9
Apr 22, 2024
Missing Authorization vulnerability
<= 5.8.3
Apr 17, 2024
Cross Site Request Forgery (CSRF) vulnerability
<= 5.7.8
Apr 8, 2024
IDOR on Friend Request vulnerability
<= 5.7.6
Apr 5, 2024
Insecure Direct Object References (IDOR) vulnerability
<= 5.7.2
Mar 28, 2024
SQL Injection vulnerability
<= 5.7.8
Mar 28, 2024
SQL Injection vulnerability
<= 5.7.8
Mar 28, 2024
Contributor+ SQL Injection vulnerability
<= 5.7.1
Mar 26, 2024
Broken Access Control vulnerability
<= 5.6.6
Dec 28, 2023
Cross Site Request Forgery (CSRF) vulnerability
<= 5.7.1
Nov 7, 2023
Authenticated (Subscriber+) Arbitrary Option Update vulnerability
<= 5.5.1
Jul 18, 2023
Hardcoded Encryption Key vulnerability
<= 5.5.0
Jul 18, 2023
Missing Authorization to Arbitrary Group Option Modification and Privilege Escalation vulnerability
<= 5.5.2
Jul 18, 2023
Missing Authorization to User Import vulnerability
<= 5.5.1
Jul 18, 2023
Broken Access Control vulnerability
<= 5.0.3
Mar 16, 2023
Subscriber+ Arbitrary Password Reset vulnerability
< 5.3.1
Mar 2, 2023
Auth. CSV Injection vulnerability
<= 5.1.6
Nov 17, 2022
Reflected Cross-Site Scripting (XSS) vulnerability
<= 5.1.0
Nov 15, 2022
Authenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 4.7.4
Jan 18, 2022
Authenticated Code Execution vulnerability
<= 2.8.5
Jun 5, 2018
Reflected Cross Site Scripting
<= 2.6.6
Nov 27, 2017