Unrated severityNVD Advisory· Published Aug 6, 2026
ProfileGrid < 6.0.0.0 - Unauthenticated Group Member List Disclosure via pm_get_all_users_from_group
CVE-2026-16290
Description
The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list, and registers the handler for unauthenticated users, allowing any unauthenticated visitor to disclose the members and their identifiers of any group, including private or closed ones, bypassing the ProfileGrid WordPress plugin before 6.0.0.0's member-visibility setting.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <6.0.0.0
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/701607f3-34b1-4f69-990b-c9ce56b58087/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.