The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions, allowing authenticated users with Subscriber-level access and above to soft-delete, tamper with the metadata of, and mark as read other users' private message threads.

Project Subscriptions

Vendors Products
Profilegrid Subscribe
Profilegrid Subscribe
Wordpress Subscribe
Wordpress Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 24 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Profilegrid
Profilegrid profilegrid
Wordpress
Wordpress wordpress
Vendors & Products Profilegrid
Profilegrid profilegrid
Wordpress
Wordpress wordpress

Fri, 24 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Description The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions, allowing authenticated users with Subscriber-level access and above to soft-delete, tamper with the metadata of, and mark as read other users' private message threads.
Title ProfileGrid < 5.9.9.7 - Subscriber+ Cross-User Private Message Thread Deletion and Tampering via Missing Authorization
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-24T06:00:02.676Z

Reserved: 2026-06-19T08:40:31.614Z

Link: CVE-2026-12689

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-24T07:30:06Z

Weaknesses

No weakness.