CVE-2026-12690: ProfileGrid < 5.9.9.7 - Subscriber+ Premium License Tampering via Missing Authorization
The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its license management actions, relying only on a nonce that is exposed to any logged-in user, allowing authenticated users with Subscriber-level access and above to overwrite the site's premium license settings.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12690?
The severity of CVE-2026-12690 is categorized as low with a CVSS score of 3.8.
How do I fix CVE-2026-12690?
To fix CVE-2026-12690, update the ProfileGrid WordPress plugin to version 5.9.9.7 or later.
What type of vulnerability is CVE-2026-12690?
CVE-2026-12690 is a security vulnerability related to Subscriber+ premium license tampering due to missing authorization checks.
Who is affected by CVE-2026-12690?
Authenticated users with Subscriber-level access and above using an affected version of the ProfileGrid plugin are at risk from CVE-2026-12690.
When was CVE-2026-12690 published?
CVE-2026-12690 was published on July 24, 2026.