What is CVE-2026-16289?
The ProfileGrid WordPress plugin before version 6.0.0.0 lacks authorization checks when listing a group's pending membership requests, allowing any authenticated user, such as a Subscriber, to view the names and request dates of users awaiting approval. This vulnerability leads to the disclosure of sensitive information for any group, including private ones.
Azərbaycanca: ProfileGrid WordPress plaqinində 6.0.0.0 versiyasından əvvəl avtorizasiya yoxlaması olmadığından, istənilən autentifikasiya olunmuş istifadəçi (məsələn, Subscriber) istənilən qrupun gözləmədə olan üzvlük sorğularını görə bilər. Bu boşluq gizli qruplar da daxil olmaqla istifadəçi adları və sorğu tarixlərinin ifşasına səbəb olur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What is CVE-2026-16289?
It is a missing authorization check in the ProfileGrid WordPress plugin. In versions prior to 6.0.0.0, any authenticated user, such as one with the Subscriber role, can view the pending membership requests of any group.
What kind of data can CVE-2026-16289 expose?
This vulnerability can lead to the disclosure of sensitive information such as the names and request dates of users awaiting approval, for any group, including private ones.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.