Unrated severityNVD Advisory· Published Aug 2, 2026· Updated Aug 4, 2026
ProfileGrid < 5.9.9.8 - Subscriber+ Arbitrary Notification Deletion via IDOR
CVE-2026-16291
Description
The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user before deleting it, allowing any authenticated user such as a Subscriber to delete other users' notifications by enumerating notification identifiers.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <5.9.9.8
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/899c2e96-39a9-4e1c-879b-40d6e629e712/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.