CVE-2026-16289: ProfileGrid < 6.0.0.0 - Subscriber+ Group Join Request Disclosure via pm_get_all_requests_from_group
The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user such as a Subscriber to disclose the names and request dates of the users awaiting approval to join any group, including private ones.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16289?
CVE-2026-16289 has a medium severity score of 4.3 according to CVSS 3.1.
How do I fix CVE-2026-16289?
To fix CVE-2026-16289, update the ProfileGrid WordPress plugin to version 6.0.0.0 or later.
What does CVE-2026-16289 allow an attacker to do?
CVE-2026-16289 allows authenticated users, like Subscribers, to disclose pending membership requests for any group.
What versions of ProfileGrid are affected by CVE-2026-16289?
CVE-2026-16289 affects all versions of the ProfileGrid WordPress plugin prior to 6.0.0.0.
Is it safe to use ProfileGrid versions below 6.0.0.0 after CVE-2026-16289 was published?
Using versions of ProfileGrid below 6.0.0.0 after the publication of CVE-2026-16289 is not safe due to the disclosed vulnerability.