PatchSiren

ProfileGrid CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review ProfileGrid CVE published 2026-08-03

CVE-2026-16289

The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests. This issue allows any authenticated user, including Subscribers, to disclose the names and request dates of users awaiting approval to join any group, including private ones. Authenticated users of WordPress sites with ProfileGrid plugin installed should be aware of pot [truncated]