
CVE-2026-16289 The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated … https://www.cve.org/CVERecord?id=CVE-2026-16289
Post summary
This announcement discloses a privilege‑escalation flaw in ProfileGrid WordPress plugin prior to version 6.0.0.0, where missing auth checks allow any authenticated user to list pending membership requests.

