CVE-2026-16290: ProfileGrid < 6.0.0.0 - Unauthenticated Group Member List Disclosure via pm_get_all_users_from_group
The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list, and registers the handler for unauthenticated users, allowing any unauthenticated visitor to disclose the members and their identifiers of any group, including private or closed ones, bypassing the ProfileGrid WordPress plugin before 6.0.0.0's member-visibility setting.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16290?
CVE-2026-16290 has a risk rating of 41, indicating a significant security vulnerability.
What does CVE-2026-16290 involve?
CVE-2026-16290 involves the ProfileGrid WordPress plugin exposing group member information to unauthenticated users.
How do I fix CVE-2026-16290?
To fix CVE-2026-16290, upgrade the ProfileGrid WordPress plugin to version 6.0.0.0 or higher.
Who is affected by CVE-2026-16290?
Any user of the ProfileGrid WordPress plugin version below 6.0.0.0 is affected by CVE-2026-16290.
What are the consequences of CVE-2026-16290?
The consequences of CVE-2026-16290 include the unauthorized disclosure of group member identities and identifiers to the public.