ProfileGrid – User Profiles, Memberships, Groups and Communities
ProfileGrid – User Profiles, Memberships, Groups and Communities (profilegrid) is a WordPress plugin with 8 published CVE records in this archive. The latest tracked vulnerability was published Aug 06, 2026; the highest published CVSS base score is 8.8.
profilegridCVE-2026-16290: ProfileGrid exposes private group membership to unauthenticated callers
ProfileGrid before 6.0.0.0 registers the pm_get_all_users_from_group AJAX action for logged-out callers. Profile_Magic_Public::pm_get_all_users_from_group() accepts attacker-controlled gid and view/search/sort/pagination parameters and passes the group identifier to the member-list query without authenticating the caller or enforcing membership visibility. An unauthenticated visitor can therefore enumerate members and identifiers for groups whose membership was intended to be private or closed. The exact returned fields beyond member output and identifiers depend on the selected view.
| Safe version |
|
||
|---|---|---|---|
| Aug 06, 2026 |
CVE-2026-16290
ProfileGrid exposes private group membership to unauthenticated callers
ProfileGrid before 6.0.0.0 registers the pm_get_all_users_from_group AJAX action for logged-out callers. Profile_Magic_Public::pm_get_all_users_from_group() accepts attacker-controlled gid and view/search/sort/pagination parameters and passes the group identifier to the member-list query without authenticating the caller or enforcing membership visibility. An unauthenticated visitor can therefore enumerate members and identifiers for groups whose membership was intended to be private or closed. The exact returned fields beyond member output and identifiers depend on the selected view.
|
6.0.0.0 |
CVE5.3
NVDPending
|
| Aug 03, 2026 |
CVE-2026-16289
ProfileGrid Subscribers can enumerate private-group applicants
ProfileGrid before 6.0.0.0 lists pending group-membership requests without an authorization check. Any authenticated user, including a Subscriber, can identify an arbitrary group and disclose the names and request dates of users awaiting approval, including applicants to private groups. The CNA record does not disclose the endpoint, group parameter or listing function.
|
6.0.0.0 |
CVE4.3
NVDPending
|
| Aug 02, 2026 |
CVE-2026-16291
ProfileGrid Subscribers can delete other users' notifications
ProfileGrid before 5.9.9.8 does not verify notification ownership before deletion. Any authenticated user, including a Subscriber, can enumerate notification identifiers and delete notifications belonging to other users. The CNA record does not disclose the endpoint, action, identifier parameter or deletion function.
|
5.9.9.8 |
CVE4.3
NVDPending
|
| Jul 30, 2026 |
CVE-2026-12687
ProfileGrid public registration can grant privileged group roles
ProfileGrid before 5.9.9.8 does not restrict which group an anonymous visitor may select during front-end registration. An unauthenticated attacker can register directly into a privileged group and receive that group's configured WordPress role, including Administrator when a site has mapped a selectable group to that role. The authoritative CNA record does not disclose the registration route, group selector parameter, handler function, or whether privileged groups must otherwise be publicly discoverable.
|
5.9.9.8 |
CVE7.5
NVDPending
|
| Oct 21, 2024 |
CVE-2024-49273
ProfileGrid: A security weakness
ProfileGrid is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.3
NVD6.5
|
| May 02, 2024 |
CVE-2024-3606
ProfileGrid – User Profiles, Memberships, Groups and Communities: A security weakness
ProfileGrid – User Profiles, Memberships, Groups and Communities is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Mar 20, 2023 |
CVE-2023-0940
ProfileGrid: A security weakness
ProfileGrid is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Nov 14, 2022 |
CVE-2022-3578
ProfileGrid: Cross-site scripting
ProfileGrid is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.1
NVD6.1
|