Description
The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its license management actions, relying only on a nonce that is exposed to any logged-in user, allowing authenticated users with Subscriber-level access and above to overwrite the site's premium license settings.
Published: 2026-07-24
Score: 3.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is present in the ProfileGrid WordPress plugin before version 5.9.9.7, where license‑management actions rely solely on a nonce that is exposed to any logged‑in user. No capability check is performed, so an authenticated user with Subscriber-level access or higher can overwrite the site’s premium license settings. This allows the user to disable or alter premium features, compromising the integrity of the plugin’s configuration and potentially disabling paid functionality. The likely attack vector is an authenticated user with Subscriber or above privileges.

Affected Systems

WordPress sites that have the ProfileGrid plugin version 5.9.9.6 or earlier are affected. Upgrading to version 5.9.9.7 or later resolves the missing authorization check and restores proper capability validation for license‑management operations.

Risk and Exploitability

The CVSS score of 3.8 indicates moderate risk, and the EPSS score below 1% implies low exploitation probability. The vulnerability is not included in the CISA KEV catalog. Because the vulnerability requires an authenticated user with at least Subscriber privileges, the attack vector is limited to legitimate site users rather than remote unauthenticated attackers. Exploitation involves submitting a request with the exposed nonce to the license‑management endpoint, bypassing the missing capability check and enabling unauthorized license changes.

Generated by OpenCVE AI on August 3, 2026 at 20:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ProfileGrid to version 5.9.9.7 or later
  • Restrict the license‑management action to Administrator users by updating the role configuration in WordPress or adding a role‑check filter
  • Verify that only Administrator users retain capability to change premium license settings by reviewing role permissions in the WordPress role editor

Generated by OpenCVE AI on August 3, 2026 at 20:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 24 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Profilegrid
Profilegrid profilegrid
Wordpress
Wordpress wordpress
Vendors & Products Profilegrid
Profilegrid profilegrid
Wordpress
Wordpress wordpress

Fri, 24 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Description The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its license management actions, relying only on a nonce that is exposed to any logged-in user, allowing authenticated users with Subscriber-level access and above to overwrite the site's premium license settings.
Title ProfileGrid < 5.9.9.7 - Subscriber+ Premium License Tampering via Missing Authorization
References

Subscriptions

Profilegrid Profilegrid
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-24T19:45:24.352Z

Reserved: 2026-06-19T08:40:34.360Z

Link: CVE-2026-12690

cve-icon Vulnrichment

Updated: 2026-07-24T19:45:19.832Z

cve-icon NVD

Status : Deferred

Published: 2026-07-24T07:16:32.680

Modified: 2026-07-24T20:48:39.923

Link: CVE-2026-12690

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T20:45:03Z

Weaknesses