CVE-2026-4607 | metagauss ProfileGrid Plugin up to 5.9.8.4 on WordPress authorization
A vulnerability described as critical has been identified in metagauss ProfileGrid Plugin up to 5.9.8.4 on WordPress. Impacted is the function pm_set_group_order/pm_set_group_items/pm_set_field_order. The manipulation results in missing authorization.
This vulnerability is reported as CVE-2026-4607. The attack can be launched remotely. No exploit exists.