CVE-2026-57697
Deferred Deferred - Pending Action

Authentication Bypass in ProfileGrid Leading to Password Recovery Exploitation

Vulnerability report for CVE-2026-57697, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-13

Last updated on: 2026-07-13

Assigner: Patchstack

Description

Authentication Bypass Using an Alternate Path or Channel vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Password Recovery Exploitation.This issue affects ProfileGrid : from n/a through <= 5.9.9.6.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-13
Last Modified
2026-07-13
Generated
2026-08-02
AI Q&A
2026-07-13
EPSS Evaluated
2026-08-01
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
metagauss profilegrid to 5.9.9.6 (inc)
metagauss profilegrid From 5.9.9 (inc) to 5.9.9.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-288 The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-57697 is an authentication bypass vulnerability in the WordPress ProfileGrid Plugin (versions 5.9.9.6 and earlier). It allows unauthenticated attackers to exploit password recovery mechanisms to perform actions normally restricted to higher-privileged users, potentially gaining administrative access to the website.

This issue is classified as a Broken Authentication vulnerability and falls under the OWASP Top 10 category A7: Identification and Authentication Failures.

Detection Guidance

Detecting CVE-2026-57697 on your network or system involves checking for the presence of the vulnerable version of the ProfileGrid plugin and testing for the authentication bypass vulnerability. Below are some methods to detect this issue.

  • Check the installed version of the ProfileGrid plugin on your WordPress site. The vulnerability affects versions up to and including 5.9.9.6. You can verify the version by navigating to the WordPress admin dashboard, going to 'Plugins', and locating the ProfileGrid plugin. If the version is 5.9.9.6 or earlier, the site is vulnerable.
  • Use a WordPress security plugin or tool to scan for known vulnerabilities. Tools like Patchstack, Wordfence, or WPScan can detect vulnerable plugin versions and report if your site is affected by CVE-2026-57697.
  • Manually test for the vulnerability by attempting to exploit the password recovery or authentication bypass mechanism. This may involve sending crafted requests to the password reset or login endpoints to see if unauthorized access is possible. However, this should only be done in a controlled environment with permission, as it may violate security policies or laws.
  • Review server logs for unusual activity related to authentication attempts or password reset requests. Look for repeated failed login attempts, unexpected password reset emails, or unauthorized access to admin-level functions.
  • Use network monitoring tools to detect anomalous traffic patterns that may indicate exploitation attempts. For example, monitor for unexpected POST requests to the WordPress login or password reset endpoints.
Impact Analysis

This vulnerability can have a significant impact as it allows attackers to bypass authentication controls without any user interaction or privileges.

  • Attackers may gain unauthorized administrative access to the affected website.
  • Such access can lead to unauthorized changes, data manipulation, or control over the website.
  • The vulnerability has a CVSS v3.1 base score of 7.5, indicating a high severity risk.
Compliance Impact

This vulnerability, an Authentication Bypass Using an Alternate Path or Channel, can significantly impact compliance with standards and regulations like GDPR and HIPAA.

  • GDPR: The vulnerability allows unauthenticated attackers to gain unauthorized access to user data or administrative functions. Under GDPR, organizations must implement appropriate technical measures to protect personal data. A breach resulting from this vulnerability could lead to unauthorized access to personal data, violating GDPR's requirements for data protection and potentially resulting in hefty fines (up to 4% of global revenue or €20 million, whichever is higher).
  • HIPAA: For organizations handling protected health information (PHI), this vulnerability could lead to unauthorized access to sensitive patient data. HIPAA requires strict access controls and safeguards to protect PHI. A breach exploiting this vulnerability could result in non-compliance with the HIPAA Security Rule, leading to penalties, legal action, or loss of certification.
  • General Compliance Risks: The vulnerability falls under OWASP Top 10 category A7 (Identification and Authentication Failures), which is a critical area for compliance frameworks. Failure to address such vulnerabilities may indicate inadequate security practices, potentially violating requirements in standards like ISO 27001, PCI DSS, or other industry-specific regulations.

Organizations using the affected plugin must apply the patch immediately to mitigate risks and maintain compliance with applicable regulations.

Mitigation Strategies

The immediate step to mitigate this vulnerability is to update the ProfileGrid WordPress plugin to version 5.9.9.7 or later, where the issue has been patched.

Users of Patchstack can also enable auto-updates for vulnerable plugins to ensure they receive security patches promptly.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-57697. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart