PatchSiren cyber security CVE debrief
CVE-2026-16290 ProfileGrid CVE debrief
The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list, allowing any unauthenticated visitor to disclose the members and their identifiers of any group, including private or closed ones, bypassing the ProfileGrid WordPress plugin's member-visibility setting. This vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. Users of the ProfileGrid WordPress plugin, especially those with private or closed groups, should be aware of this vulnerability and take necessary actions to protect their group member lists. The CVE record was published on 2026-08-06T07:16:28.410Z and has not been modified since then. Evidence is limited to public CVE and NVD records. Defenders should verify affected deployments, review official advisories, and plan vendor-supported updates or mitigations.
- Vendor
- ProfileGrid
- Product
- ProfileGrid WordPress plugin
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-06
- Original CVE updated
- 2026-08-06
- Advisory published
- 2026-08-06
- Advisory updated
- 2026-08-06
Who should care
Users of the ProfileGrid WordPress plugin, especially those with private or closed groups, should be aware of this vulnerability and take necessary actions to protect their group member lists. This includes verifying the plugin version, restricting access to group member lists, and monitoring for potential unauthorized access. Security teams and vulnerability management teams should also review the official advisory and plan vendor-supported updates or mitigations.
Technical summary
The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list. This allows any unauthenticated visitor to disclose the members and their identifiers of any group, including private or closed ones, bypassing the ProfileGrid WordPress plugin's member-visibility setting. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. The issue arises from the plugin's failure to validate requests for group member lists, which can lead to unauthorized disclosure of sensitive information. Users of the plugin should verify their version and upgrade to 6.0.0.0 or later if necessary. Security teams should review the official advisory and plan vendor-supported updates or mitigations.
Defensive priority
Medium priority given the CVSS score of 5.3 and the potential for unauthorized disclosure of group member lists.
Recommended defensive actions
- Verify the ProfileGrid WordPress plugin version and upgrade to 6.0.0.0 or later if necessary.
- Restrict access to group member lists to authorized users only.
- Monitor for potential unauthorized access to group member lists.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list. Official records indicate a CVSS score of 5.3 and MEDIUM severity. The vulnerability allows any unauthenticated visitor to disclose the members and their identifiers of any group, including private or closed ones, bypassing the ProfileGrid WordPress plugin's member-visibility setting. Evidence is limited to public CVE and NVD records. Defenders should verify affected deployments, review official advisories, and plan vendor-supported updates or mitigations.
Official resources
-
CVE-2026-16290 CVE record
CVE.org
-
CVE-2026-16290 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T07:16:28.410Z and has not been modified since then.