๐Ÿ” CVE Alert

CVE-2026-12687

HIGH 7.5

ProfileGrid < 5.9.9.8 - Unauthenticated Privilege Escalation via Unrestricted Group ID

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into through its front-end registration, allowing unauthenticated users to register directly into a privileged group and be granted that group's configured role, up to Administrator when such a group exists, leading to privilege escalation.

Vendor unknown
Product profilegrid
Published Jul 30, 2026
Last Updated Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for unknown profilegrid

Be the first to know when new high vulnerabilities affecting unknown profilegrid are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / ProfileGrid
0 < 5.9.9.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/e754ef68-40ae-4420-a0b8-6c23a83bc450/

Credits

Revanth Hari Narayana Matte WPScan