CVE-2026-2488Disclosure

LOWCVSS 4.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized message deletion due to a missing capability check on the pg_delete_msg() function in all versions up to, and including, 5.9.8.1. This is due to the function not verifying that the requesting user has permission to delete the targeted message. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary messages belonging to any user by sending a direct request with a valid message ID (mid parameter).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-07: 2Technical Details · 2026-03-07: 203-07
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-2488 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized message deletion due to a missing capability check on the pg_… https://www.cve.org/CVERecord?id=CVE-2026-2488 ----- Traducción: CVE-2026-2488 El … http://infoflow.cloud`

    Post summary

    A newly disclosed CVE-2026-2488 affects the ProfileGrid WordPress plugin, enabling unauthorized message deletion caused by a missing capability check.

    0000021
    56 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2488 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized message deletion due to a missing capability check on the pg_… https://www.cve.org/CVERecord?id=CVE-2026-2488

    Post summary

    The CVE-2026-2488 entry reports that the ProfileGrid WordPress plugin allows unauthorized message deletion due to a missing capability check, but no PoC, exploitation code, or patch information is provided.

    00000165
    56.6K followersView on X

Explore more