CVE-2026-16290 PUBLISHED

ProfileGrid < 6.0.0.0 - Unauthenticated Group Member List Disclosure via pm_get_all_users_from_group

Assigner: WPScan
Reserved: 20.07.2026 Published: 06.08.2026 Updated: 06.08.2026

The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list, and registers the handler for unauthenticated users, allowing any unauthenticated visitor to disclose the members and their identifiers of any group, including private or closed ones, bypassing the ProfileGrid WordPress plugin before 6.0.0.0's member-visibility setting.

Product Status

Vendor Unknown
Product ProfileGrid
Versions Default: unaffected
  • affected from 0 to 6.0.0.0 (excl.)

Credits

  • Meher Sudhakar Abbireddi finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE