CVE-2026-16289 UNKNOWN

CVE-2026-16289

Published: 2026-08-03

Description

The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user such as a Subscriber to disclose the names and request dates of the users awaiting approval to join any group, including private ones.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…