What is CVE-2026-12687?
CVE-2026-12687 is a critical vulnerability in the ProfileGrid WordPress plugin, allowing unauthenticated users to register directly into privileged groups, up to Administrator level, via its front-end registration. Affecting versions prior to 5.9.9.8, it grants attackers immediate administrative control. Immediate update to the latest version is required.
Azərbaycanca: CVE-2026-12687, ProfileGrid WordPress plaginində anonim qeydiyyat zamanı istifadəçilərin, o cümlədən Administrator səviyyəsinə qədər imtiyazlı qruplara birbaşa qeydiyyatdan keçməsinə imkan verən kritik zəiflikdir. 5.9.9.8 versiyasından əvvəlki plaginlərdə mövcud olan bu boşluq identifikasiya olunmamış hücumçulara saytda inzibati nəzarəti ələ keçirməyə şərait yaradır. Plaginin dərhal ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-269
FAQ2
What can an attacker gain by exploiting CVE-2026-12687?
By registering directly into privileged groups up to Administrator level via anonymous registration, the attacker can gain administrative control over the site.
What should be done to mitigate CVE-2026-12687 in the ProfileGrid plugin?
Since versions prior to 5.9.9.8 are affected, immediate update to the latest version is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.