CVE-2026-12689: ProfileGrid < 5.9.9.7 - Subscriber+ Cross-User Private Message Thread Deletion and Tampering via Missing Authorization
The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions, allowing authenticated users with Subscriber-level access and above to soft-delete, tamper with the metadata of, and mark as read other users' private message threads.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12689?
CVE-2026-12689 has a medium severity rating of 5.4 based on the CVSS 3.1 score.
How do I fix CVE-2026-12689?
To fix CVE-2026-12689, update the ProfileGrid WordPress plugin to version 5.9.9.7 or later.
What actions can be exploited in CVE-2026-12689?
CVE-2026-12689 allows authenticated users to soft-delete and tamper with other users' private message threads.
Who is affected by CVE-2026-12689?
All users with Subscriber-level access and above on the ProfileGrid WordPress plugin before version 5.9.9.7 are affected by CVE-2026-12689.
What impact does CVE-2026-12689 have on user privacy?
CVE-2026-12689 can lead to unauthorized modification of private message threads, compromising user privacy.