CVE-2026-16291

The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user before deleting it, allowing any authenticated user such as a Subscriber to delete other users' notifications by enumerating notification identifiers.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-02 06:16

Updated : 2026-08-26 16:31


NVD link : CVE-2026-16291

Mitre link : CVE-2026-16291

CVE.ORG link : CVE-2026-16291


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key