CVE-2026-16289 PUBLISHED

ProfileGrid < 6.0.0.0 - Subscriber+ Group Join Request Disclosure via pm_get_all_requests_from_group

Assigner: WPScan
Reserved: 20.07.2026 Published: 03.08.2026 Updated: 03.08.2026

The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user such as a Subscriber to disclose the names and request dates of the users awaiting approval to join any group, including private ones.

Product Status

Vendor Unknown
Product ProfileGrid
Versions Default: unaffected
  • affected from 0 to 6.0.0.0 (excl.)

Credits

  • Meher Sudhakar Abbireddi finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE