CVE-2026-16289

Published: Ago 03, 2026 Last Modified: Ago 03, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user such as a Subscriber to disclose the names and request dates of the users awaiting approval to join any group, including private ones.

https://wpscan.com/vulnerability/815a2245-6477-42a1-b08a-fa308a830be3/