PT-2026-23816 · WordPress · Profilegrid – User Profiles

Boris Bogosavac

+1

·

Published

2026-03-07

·

Updated

2026-03-07

·

CVE-2026-2488

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions ProfileGrid – User Profiles, Groups and Communities plugin for WordPress versions up to and including 5.9.8.1
Description The ProfileGrid plugin for WordPress is affected by an issue allowing unauthorized message deletion. This occurs because the pg delete msg() function lacks a proper capability check, enabling authenticated attackers with Subscriber-level access or higher to delete messages belonging to any user. Exploitation involves sending a direct request with a valid message ID through the mid parameter.
Recommendations Update ProfileGrid – User Profiles, Groups and Communities plugin for WordPress to a version later than 5.9.8.1.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-2488

Affected Products

Profilegrid – User Profiles