Review
ProfileGrid
CVE published 2026-08-03
CVE-2026-16289
The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests. This issue allows any authenticated user, including Subscribers, to disclose the names and request dates of users awaiting approval to join any group, including private ones. Authenticated users of WordPress sites with ProfileGrid plugin installed should be aware of pot [truncated]