Junglewise Threat Intelligence

CVE-2026-12687: ProfileGrid WordPress plugin unauthenticated privilege escalation

CVE-2026-12687 · Severity: info · CVSS 8.1 · Published 2026-07-30

Technologies: ProfileGrid. Vendors: ProfileGrid.

Executive brief

A vulnerability in the ProfileGrid WordPress plugin, which is used for managing user profiles and communities, allows unauthorized visitors to gain administrative control over a website. By exploiting a flaw in the registration process, an attacker can sign up for a new account and assign themselves to a high-privilege group, such as Administrator. This could lead to a complete takeover of the website, allowing the attacker to steal data, modify content, or lock out legitimate owners.

Technical details

The ProfileGrid plugin for WordPress suffers from an unauthenticated privilege escalation vulnerability due to missing authorization checks during the front-end registration process. The plugin does not validate or restrict the 'group ID' parameter provided during registration, allowing an anonymous user to specify a privileged group ID. If a group is configured to grant a high-level WordPress role (such as Administrator), the registrant is automatically assigned that role upon account creation. This allows a remote, unauthenticated attacker to gain full administrative access to the WordPress site. The issue is resolved in version 5.9.9.8.

Affected products

  • ProfileGrid ProfileGrid before 5.9.9.8

Timeline

  • 2026-07-10: disclosed
  • 2026-07-30: advisory: NVD publication date
  • patched: Fixed in version 5.9.9.8

References

Related threats