Unrated severityNVD Advisory· Published Aug 3, 2026· Updated Aug 3, 2026
ProfileGrid < 6.0.0.0 - Subscriber+ Group Join Request Disclosure via pm_get_all_requests_from_group
CVE-2026-16289
Description
The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user such as a Subscriber to disclose the names and request dates of the users awaiting approval to join any group, including private ones.
Affected products
1- Range: <6.0.0.0
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/815a2245-6477-42a1-b08a-fa308a830be3/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.