CVE-2026-16289
Received Received - Intake

Authorization Bypass in ProfileGrid WordPress Plugin

Vulnerability report for CVE-2026-16289, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: WPScan

Description

The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user such as a Subscriber to disclose the names and request dates of the users awaiting approval to join any group, including private ones.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-03
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
profilegrid profilegrid to 6.0.0.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The ProfileGrid WordPress plugin before version 6.0.0.0 has a vulnerability where it fails to check user permissions when displaying pending membership requests for groups. This allows any logged-in user, even those with minimal access like Subscribers, to view the names and request dates of users waiting to join any group, including private ones.

Detection Guidance

Check WordPress sites running ProfileGrid plugin versions before 6.0.0.0. Inspect network traffic for unauthorized requests to /wp-json/profilegrid/v1/groups/{group_id}/pending-members. Review server logs for repeated access to membership endpoints by low-privilege users.

Impact Analysis

This vulnerability could expose sensitive information about group memberships. Attackers might use this to identify potential targets, gather intelligence on private groups, or prepare for further attacks by knowing who is trying to join restricted groups.

Mitigation Strategies

Update ProfileGrid plugin to version 6.0.0.0 or later immediately. Implement strict access controls to restrict endpoint access. Monitor for unauthorized group membership disclosures and audit user permissions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16289. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart