The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user such as a Subscriber to disclose the names and request dates of the users awaiting approval to join any group, including private ones.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 03 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Profilegrid
Profilegrid profilegrid
Wordpress
Wordpress wordpress
Weaknesses CWE-284
Vendors & Products Profilegrid
Profilegrid profilegrid
Wordpress
Wordpress wordpress

Mon, 03 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user such as a Subscriber to disclose the names and request dates of the users awaiting approval to join any group, including private ones.
Title ProfileGrid < 6.0.0.0 - Subscriber+ Group Join Request Disclosure via pm_get_all_requests_from_group
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-03T16:19:22.633Z

Reserved: 2026-07-20T12:19:37.183Z

Link: CVE-2026-16289

cve-icon Vulnrichment

Updated: 2026-08-03T16:19:02.869Z

cve-icon NVD

Status : Received

Published: 2026-08-03T07:16:41.240

Modified: 2026-08-03T17:16:30.640

Link: CVE-2026-16289

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T10:45:05Z

Weaknesses