PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-16289 ProfileGrid CVE debrief

The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests. This issue allows any authenticated user, including Subscribers, to disclose the names and request dates of users awaiting approval to join any group, including private ones. Authenticated users of WordPress sites with ProfileGrid plugin installed should be aware of potential group membership request disclosure. The CVE record was published on 2026-08-03T07:16:41.240Z and has not been modified since then. Evidence is limited to public sources and may not cover all affected systems. Defenders should verify group membership request disclosure with additional checks.

Vendor
ProfileGrid
Product
ProfileGrid WordPress plugin
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-03
Original CVE updated
2026-08-03
Advisory published
2026-08-03
Advisory updated
2026-08-03

Who should care

Authenticated users of WordPress sites with ProfileGrid plugin installed should be aware of potential group membership request disclosure. Operators, platform administrators, vulnerability management teams, and security teams may need to review and verify affected systems.

Technical summary

The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user to disclose the names and request dates of users awaiting approval to join any group, including private ones. This issue affects WordPress sites with ProfileGrid plugin installed. Operators, platform administrators, vulnerability management teams, and security teams may need to review and verify affected systems. The ProfileGrid plugin's missing authorization checks can lead to unauthorized disclosure of sensitive information, including user names and group membership requests.

Defensive priority

Authenticated users should verify group membership request disclosure.

Recommended defensive actions

  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Inventory and verify ProfileGrid plugin version.

Evidence notes

The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests. Official CVE and NVD records provide limited detail. Evidence is limited to public sources and may not cover all affected systems. Defenders should verify group membership request disclosure with additional checks.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-03T07:16:41.240Z and has not been modified since then.