CVE-2026-12687: ProfileGrid < 5.9.9.8 - Unauthenticated Privilege Escalation via Unrestricted Group ID
The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into through its front-end registration, allowing unauthenticated users to register directly into a privileged group and be granted that group's configured role, up to Administrator when such a group exists, leading to privilege escalation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ProfileGrid (WordPress plugin)to a version that resolves this vulnerability.Fixed in 5.9.9.8
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12687?
CVE-2026-12687 has a high severity rating of 7.5 according to CVSS 3.1.
What vulnerability is associated with CVE-2026-12687?
CVE-2026-12687 is associated with an unauthenticated privilege escalation in the ProfileGrid WordPress plugin.
How do I fix CVE-2026-12687?
To fix CVE-2026-12687, update the ProfileGrid plugin to version 5.9.9.8 or later.
What impact does CVE-2026-12687 have on my website?
CVE-2026-12687 allows unauthenticated users to register into privileged groups, potentially granting them administrative access.
Which software is affected by CVE-2026-12687?
The ProfileGrid WordPress plugin versions prior to 5.9.9.8 are affected by CVE-2026-12687.