What is CVE-2026-12689?
CVE-2026-12689 is an authorization bypass vulnerability in the ProfileGrid WordPress plugin before version 5.9.9.7, affecting private-message thread actions. It allows authenticated users with Subscriber-level access to soft-delete, tamper with metadata, and mark as read other users' private messages. Updating to the latest plugin version is strongly recommended.
Azərbaycanca: CVE-2026-12689, WordPress üçün ProfileGrid plagininin 5.9.9.7-dən əvvəlki versiyalarında avtorizasiya yoxlanışının olmaması ilə bağlıdır. Bu boşluq Subscriber səviyyəsində autentifikasiya olunmuş istifadəçilərə başqalarının şəxsi mesajlarını silmək, metadata ilə manipulyasiya etmək və oxunmuş kimi işarələmək imkanı verir. Plaginin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What plugin is affected by CVE-2026-12689 and what causes the vulnerability?
This vulnerability occurs in the ProfileGrid WordPress plugin before version 5.9.9.7 due to an authorization bypass.
What actions can a Subscriber-level user perform by exploiting CVE-2026-12689?
An authenticated user with Subscriber-level access can soft-delete, tamper with metadata, and mark as read other users' private messages.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.