Security Advisory

CVE-2026-16289

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-03 06:00:13
Last updated 2026-08-03 16:19:22
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user such as a Subscriber to disclose the names and request dates of the users awaiting approval to join any group, including private ones.