Metagauss develops a focused suite of WordPress plugins and themes for community engagement, user registration, and event management, products that sit within millions of WordPress deployments despite limited vendor breadth. Its vulnerability profile concentrates in access-control and input-handling weaknesses endemic to web applications—missing authorization, cross-site scripting, CSRF, SQL injection, and authorization-bypass flaws—reflecting the intersection of plugin architecture, user-facing forms, and database interaction inherent to these tools. The vendor's disclosures span a meaningful share of serious-severity outcomes, and the recurrence of these foundational web-layer weakness classes across multiple products underscores the sustained importance of defensive coding practices in extensible platform ecosystems. Defenders should review any Metagauss plugins or themes in active use and prioritize patches addressing authorization and injection-class flaws; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Metagauss over time
Signals from CVEs in this vendor scope (128 CVEs).
128 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24862HIGH The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in bat | Jan 10, 2022 | 7.2 | 86 | NO | YES |
CVE-2021-4073HIGH The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site du | Dec 14, 2021 | 8.1 | 43 | NO | YES |
CVE-2024-30491HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8. | Mar 29, 2024 | 8.8 | 40 | NO | NO |
CVE-2024-30490CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8. | Mar 29, 2024 | 9.8 | 40 | NO | YES |
CVE-2026-57759HIGH Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions. | Jul 2, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-49764CRITICAL Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions. | Jun 15, 2026 | 9.8 | 35 | NO | NO |
CVE-2026-57697HIGH Authentication Bypass Using an Alternate Path or Channel vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Password Recovery Exploitat | Jul 13, 2026 | 7.5 | 33 | NO | NO |
CVE-2022-3578MEDIUM The ProfileGrid WordPress plugin before 5.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting | Nov 14, 2022 | 6.1 | 32 | NO | YES |
CVE-2026-24378CRITICAL Deserialization of Untrusted Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Object Injection.This issue affects EventPrime: from n/a through | Mar 25, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-24380HIGH Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue | Jan 22, 2026 | 8.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (128 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Metagauss.
Media articles that mention a CVE ID that affects a product developed by Metagauss — matched by CVE ID, not by vendor name.