CVE-2026-16291: Unknown Profilegrid

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user before deleting it, allowing any authenticated user such as a Subscriber to delete other users' notifications by enumerating notification identifiers.

Affected products

  • Unknown Profilegrid: before 5.9.9.8 (fixed in 5.9.9.8)

Published 2026-08-02. Last modified 2026-08-26.