What is CVE-2026-16290?
CVE-2026-16290 allows unauthenticated visitors to disclose member lists and identifiers of any group, including private ones, in the ProfileGrid WordPress plugin before version 6.0.0.0 due to missing authorization checks. Update the plugin to the latest patched version to fix this vulnerability.
Azərbaycanca: CVE-2026-16290, ProfileGrid WordPress plaqinində avtorizasiya yoxlanışı olmaması səbəbindən autentifikasiya olunmamış istifadəçilərə qrupların üzv siyahısını və identifikatorlarını ifşa etməyə imkan verir. Bu, 6.0.0.0 versiyasından əvvəlki bütün plaqin versiyalarına təsir edir. Plaqini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ1
Which versions of the ProfileGrid plugin are affected by CVE-2026-16290?
This vulnerability affects all versions of the ProfileGrid WordPress plugin before version 6.0.0.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.