CVE-2026-16289

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/08/2026
Last modified:
03/08/2026

Description

The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user such as a Subscriber to disclose the names and request dates of the users awaiting approval to join any group, including private ones.