What is CVE-2026-16291?
CVE-2026-16291 is a vulnerability in the ProfileGrid WordPress plugin (versions before 5.9.9.8) due to missing authorization checks when deleting notifications. Any authenticated user, such as a Subscriber, can exploit this to delete other users' notifications by enumerating notification IDs. Update the plugin to version 5.9.9.8 or later to remediate this issue.
Azərbaycanca: CVE-2026-16291 zəifliyi ProfileGrid WordPress plaginində (5.9.9.8-dən əvvəlki versiyalarda) aşkarlanıb. Bu, autentifikasiya olunmuş istənilən istifadəçiyə (məsələn, Subscriber rolunda) digər istifadəçilərin bildirişlərini silməyə imkan verən authorization yoxlanışının olmamasıdır. Təsirə məruz qalmamaq üçün plagini ən azı 5.9.9.8 versiyasına yeniləmək lazımdır.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
In which plugin was CVE-2026-16291 discovered and what is its cause?
CVE-2026-16291 was discovered in the ProfileGrid WordPress plugin, in versions before 5.9.9.8. The cause is missing authorization checks when deleting notifications.
What can a user exploiting this vulnerability do?
Any authenticated user, such as a Subscriber, can delete other users' notifications by enumerating notification IDs.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.