PatchSiren cyber security CVE debrief
CVE-2026-16289 ProfileGrid CVE debrief
The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests. This issue allows any authenticated user, including Subscribers, to disclose the names and request dates of users awaiting approval to join any group, including private ones. Authenticated users of WordPress sites with ProfileGrid plugin installed should be aware of potential group membership request disclosure. The CVE record was published on 2026-08-03T07:16:41.240Z and has not been modified since then. Evidence is limited to public sources and may not cover all affected systems. Defenders should verify group membership request disclosure with additional checks.
- Vendor
- ProfileGrid
- Product
- ProfileGrid WordPress plugin
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-03
- Original CVE updated
- 2026-08-03
- Advisory published
- 2026-08-03
- Advisory updated
- 2026-08-03
Who should care
Authenticated users of WordPress sites with ProfileGrid plugin installed should be aware of potential group membership request disclosure. Operators, platform administrators, vulnerability management teams, and security teams may need to review and verify affected systems.
Technical summary
The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user to disclose the names and request dates of users awaiting approval to join any group, including private ones. This issue affects WordPress sites with ProfileGrid plugin installed. Operators, platform administrators, vulnerability management teams, and security teams may need to review and verify affected systems. The ProfileGrid plugin's missing authorization checks can lead to unauthorized disclosure of sensitive information, including user names and group membership requests.
Defensive priority
Authenticated users should verify group membership request disclosure.
Recommended defensive actions
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Inventory and verify ProfileGrid plugin version.
Evidence notes
The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests. Official CVE and NVD records provide limited detail. Evidence is limited to public sources and may not cover all affected systems. Defenders should verify group membership request disclosure with additional checks.
Official resources
-
CVE-2026-16289 CVE record
CVE.org
-
CVE-2026-16289 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-03T07:16:41.240Z and has not been modified since then.