← back
CVE-2026-16289

ProfileGrid < 6.0.0.0 - Subscriber+ Group Join Request Disclosure via pm_get_all_requests_from_group

0Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Track
exploitation probability
observed exploitation
nono source reports it
The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user such as a Subscriber to disclose the names and request dates of the users awaiting approval to join any group, including private ones.
Affected products
Unknown · ProfileGrid