Description
The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list, and registers the handler for unauthenticated users, allowing any unauthenticated visitor to disclose the members and their identifiers of any group, including private or closed ones, bypassing the ProfileGrid WordPress plugin before 6.0.0.0's member-visibility setting.
Published: 2026-08-06
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The ProfileGrid WordPress plugin before version 6.0.0.0 fails to perform authorization checks before returning a group's member list. The handler is registered for unauthenticated requests, allowing any visitor to retrieve the members and identifiers of any group, including those that are private or closed. This results in a privacy breach where sensitive membership information is exposed without consent and bypasses the plugin’s intended visibility controls.

Affected Systems

WordPress sites that have installed the ProfileGrid plugin with any version lower than 6.0.0.0 are affected. The vulnerability applies to all such installations, regardless of the number or type of groups present.

Risk and Exploitability

The flaw can be exploited by simply accessing a URL exposed by the plugin; no authentication or special privileges are required. The CVSS score of 5.3 indicates a moderate risk level, while the EPSS score of < 1% suggests a low probability of exploitation in the wild. The KEV status indicates it is not listed in CISA's Known Exploited Vulnerabilities catalog, so active exploitation is currently considered unlikely.

Generated by OpenCVE AI on August 6, 2026 at 18:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the ProfileGrid plugin to version 6.0.0.0 or later.
  • If upgrading is not immediately possible, disable or restrict the pm_get_all_users_from_group endpoint so only authenticated users can access it.
  • Reconfigure group visibility settings to limit which member information can be retrieved by the plugin, ensuring that sensitive groups remain private.

Generated by OpenCVE AI on August 6, 2026 at 18:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Thu, 06 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Profilegrid
Profilegrid profilegrid
Wordpress
Wordpress wordpress
Vendors & Products Profilegrid
Profilegrid profilegrid
Wordpress
Wordpress wordpress

Thu, 06 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Thu, 06 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list, and registers the handler for unauthenticated users, allowing any unauthenticated visitor to disclose the members and their identifiers of any group, including private or closed ones, bypassing the ProfileGrid WordPress plugin before 6.0.0.0's member-visibility setting.
Title ProfileGrid < 6.0.0.0 - Unauthenticated Group Member List Disclosure via pm_get_all_users_from_group
References

Subscriptions

Profilegrid Profilegrid
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-06T14:29:21.620Z

Reserved: 2026-07-20T12:19:40.200Z

Link: CVE-2026-16290

cve-icon Vulnrichment

Updated: 2026-08-06T14:29:17.604Z

cve-icon NVD

Status : Deferred

Published: 2026-08-06T07:16:28.410

Modified: 2026-08-26T16:31:16.753

Link: CVE-2026-16290

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T18:30:04Z

Weaknesses