CVE-2026-16289: Unknown Profilegrid
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user such as a Subscriber to disclose the names and request dates of the users awaiting approval to join any group, including private ones.
Affected products
- Unknown Profilegrid: before 6.0.0.0 (fixed in 6.0.0.0)
Published 2026-08-03. Last modified 2026-08-26.