CVE-2026-16291
Received Received - Intake

Authenticated User Notification Deletion in ProfileGrid WordPress Plugin

Vulnerability report for CVE-2026-16291, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-02

Last updated on: 2026-08-02

Assigner: WPScan

Description

The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user before deleting it, allowing any authenticated user such as a Subscriber to delete other users' notifications by enumerating notification identifiers.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-02
Last Modified
2026-08-02
Generated
2026-08-02
AI Q&A
2026-08-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
profilegrid profilegrid to 5.9.9.8 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The ProfileGrid WordPress plugin before version 5.9.9.8 has a vulnerability where it does not check if a notification belongs to the user making the request before deleting it. This allows any authenticated user, including low-privilege users like Subscribers, to delete notifications of other users by guessing or enumerating notification IDs.

Detection Guidance

Check for unauthorized deletion of notifications in WordPress logs or database. Look for suspicious activity from Subscriber-level accounts. No specific commands are provided in the context.

Impact Analysis

This vulnerability can lead to unauthorized deletion of other users' notifications, potentially causing loss of important information, disrupting workflows, or enabling social engineering attacks by removing critical alerts meant for other users.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it involves unauthorized deletion of notifications rather than data exposure or privacy breaches. However, if notifications contained sensitive user data, improper access could indirectly impact compliance.

Mitigation Strategies

Update the ProfileGrid plugin to version 5.9.9.8 or later. Restrict Subscriber-level access to sensitive functions. Monitor notification deletion logs for anomalies.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16291. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart