CVE-2026-16291: ProfileGrid < 5.9.9.8 - Subscriber+ Arbitrary Notification Deletion via IDOR
Published Aug 2, 2026
·Updated
The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user before deleting it, allowing any authenticated user such as a Subscriber to delete other users' notifications by enumerating notification identifiers.
Affected Software
1 affected component
ProfileGrid WordPress plugin<5.9.9.8
Event History
Aug 2, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:16 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-16291?
The severity of CVE-2026-16291 is rated at risk level 35.
2
How do I fix CVE-2026-16291?
To fix CVE-2026-16291, upgrade the ProfileGrid WordPress plugin to version 5.9.9.8 or later.
3
Who is affected by CVE-2026-16291?
Anyone using the ProfileGrid WordPress plugin versions prior to 5.9.9.8 is affected by CVE-2026-16291.
4
What type of attack does CVE-2026-16291 enable?
CVE-2026-16291 enables an authenticated user, such as a Subscriber, to delete other users' notifications through insecure direct object references.
5
When was CVE-2026-16291 published?
CVE-2026-16291 was published on August 2, 2026.