PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-16290 ProfileGrid CVE debrief

The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list, allowing any unauthenticated visitor to disclose the members and their identifiers of any group, including private or closed ones, bypassing the ProfileGrid WordPress plugin's member-visibility setting. This vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. Users of the ProfileGrid WordPress plugin, especially those with private or closed groups, should be aware of this vulnerability and take necessary actions to protect their group member lists. The CVE record was published on 2026-08-06T07:16:28.410Z and has not been modified since then. Evidence is limited to public CVE and NVD records. Defenders should verify affected deployments, review official advisories, and plan vendor-supported updates or mitigations.

Vendor
ProfileGrid
Product
ProfileGrid WordPress plugin
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-06
Original CVE updated
2026-08-06
Advisory published
2026-08-06
Advisory updated
2026-08-06

Who should care

Users of the ProfileGrid WordPress plugin, especially those with private or closed groups, should be aware of this vulnerability and take necessary actions to protect their group member lists. This includes verifying the plugin version, restricting access to group member lists, and monitoring for potential unauthorized access. Security teams and vulnerability management teams should also review the official advisory and plan vendor-supported updates or mitigations.

Technical summary

The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list. This allows any unauthenticated visitor to disclose the members and their identifiers of any group, including private or closed ones, bypassing the ProfileGrid WordPress plugin's member-visibility setting. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. The issue arises from the plugin's failure to validate requests for group member lists, which can lead to unauthorized disclosure of sensitive information. Users of the plugin should verify their version and upgrade to 6.0.0.0 or later if necessary. Security teams should review the official advisory and plan vendor-supported updates or mitigations.

Defensive priority

Medium priority given the CVSS score of 5.3 and the potential for unauthorized disclosure of group member lists.

Recommended defensive actions

  • Verify the ProfileGrid WordPress plugin version and upgrade to 6.0.0.0 or later if necessary.
  • Restrict access to group member lists to authorized users only.
  • Monitor for potential unauthorized access to group member lists.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list. Official records indicate a CVSS score of 5.3 and MEDIUM severity. The vulnerability allows any unauthenticated visitor to disclose the members and their identifiers of any group, including private or closed ones, bypassing the ProfileGrid WordPress plugin's member-visibility setting. Evidence is limited to public CVE and NVD records. Defenders should verify affected deployments, review official advisories, and plan vendor-supported updates or mitigations.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T07:16:28.410Z and has not been modified since then.