๐Ÿ” CVE Alert

CVE-2026-12689

UNKNOWN 0.0

ProfileGrid < 5.9.9.7 - Subscriber+ Cross-User Private Message Thread Deletion and Tampering via Missing Authorization

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions, allowing authenticated users with Subscriber-level access and above to soft-delete, tamper with the metadata of, and mark as read other users' private message threads.

Vendor unknown
Product profilegrid
Published Jul 24, 2026
Stay Ahead of the Next One

Get instant alerts for unknown profilegrid

Be the first to know when new unknown vulnerabilities affecting unknown profilegrid are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / ProfileGrid
0 < 5.9.9.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/7368fe32-9415-47c3-b94b-b85ca1a0d101/

Credits

Revanth Hari Narayana Matte WPScan