๐Ÿ” CVE Alert

CVE-2026-12690

UNKNOWN 0.0

ProfileGrid < 5.9.9.7 - Subscriber+ Premium License Tampering via Missing Authorization

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its license management actions, relying only on a nonce that is exposed to any logged-in user, allowing authenticated users with Subscriber-level access and above to overwrite the site's premium license settings.

Vendor unknown
Product profilegrid
Published Jul 24, 2026
Stay Ahead of the Next One

Get instant alerts for unknown profilegrid

Be the first to know when new unknown vulnerabilities affecting unknown profilegrid are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / ProfileGrid
0 < 5.9.9.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/7a1fc208-851b-4eb6-a332-fbef57181755/

Credits

Revanth Hari Narayana Matte WPScan