CVE-2026-12073Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.9.9.5. This is due to the plugin not validating a `user_login` on registration forms that don't contain this parameter, and not properly handling the error messages. This makes it possible for unauthenticated attackers to change email address of user account with ID=1 (usually an administrator), and leverage that to reset the user's password and gain access to their account.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-06-30); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-06-30: 3Mentions · 2026-07-05: 1Patch / Workaround · 2026-06-30: 2Patch / Workaround · 2026-07-05: 1Technical Details · 2026-06-30: 2Technical Details · 2026-07-05: 106-3007-05
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-303
Disclosure1General1Patch1
2026-07-051
Disclosure1
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-12073 Privilege Escalation via Account Takeover in ProfileGrid WordPress Plugin 5.9.9.5 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-12073

    Post summary

    The post notes a CVE for a WordPress plugin and links to details, but offers no information on exploit code, active exploitation, patches, or technical depth.

    01010116
    4.1K followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    👤 CVE-2026-12073: ProfileGrid WordPress plugin (≤5.9.9.5) has a CVSS 9.8 unauthenticated privilege escalation flaw. Attackers can overwrite account emails and take over any user account. Update immediately. #WordPress #infosec https://secalerts.co/vulnerability/CVE-2026-12073?utm_campaign=x https://t.co/foRFSG58Jy

    Post summary

    The tweet discloses a high‑severity vulnerability (CVE‑2026‑12073) in the ProfileGrid WordPress plugin that allows unauthenticated attackers to overwrite user emails and take over accounts, urging users to update immediately.

    00001105
    849 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-12073 — CVSS 9.8/10 ██████████ The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/MP4uwZNMaD

    Post summary

    The tweet alerts about a critical privilege escalation flaw in the WordPress ProfileGrid plugin, highlights its high CVSS score, and urges users to apply the available patch immediately.

    1000081
    63 followersView on X
  • ADK Cyber@ADKCyber
    Disclosure

    WordPress sites using ProfileGrid plugin (≤5.9.9.5) face high risk from CVE-2026-12073 (CVSS 9.8) due to privilege escalation. Check and update installations. https://nvd.nist.gov/vuln/detail/… via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/99JETLZbhl

    Post summary

    The tweet warns WordPress users of a high‑risk privilege escalation flaw (CVE‑2026‑12073) in the ProfileGrid plugin, urging updates, with no evidence of PoC, exploit code, or active attacks.

    0000050
    92 followersView on X

Explore more