SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-11359

MEDIUM · CVSS 4.3 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-07-09 · Last synced 2026-08-08

CyberRota Analysis

AI-Generated

The Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration plugin for WordPress is vulnerable to unauthorized installation and activation of the ProfileGrid plugin due to inadequate capability checks and nonce validation. This flaw allows authenticated attackers with Subscriber-level access or higher to exploit the AJAX handler and compromise the site. WordPress site administrators using this plugin should prioritize patching to mitigate potential unauthorized plugin installations.

CVE
CVE-2026-11359
Severity
MEDIUM
CVSS
4.3
EPSS
0.25%
WordPress

Original NVD Description

The Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration plugin for WordPress is vulnerable to unauthorized plugin installation and activation in versions up to, and including, 3.4. This is due to a missing capability check and missing nonce validation on the pg_install_profilegrid() AJAX handler registered via wp_ajax_pg_install_profilegrid. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate the ProfileGrid plugin from wordpress.