Junglewise Threat Intelligence

CVE-2026-16291: ProfileGrid arbitrary notification deletion via IDOR

CVE-2026-16291 · Severity: medium · CVSS 4.3 · Published 2026-08-02

Technologies: ProfileGrid. Vendors: ProfileGrid.

Executive brief

ProfileGrid is a WordPress plugin for user profiles, groups, and communities. The plugin fails to verify that a user owns a notification before allowing deletion, enabling any logged-in subscriber to delete other users' notifications by guessing sequential notification IDs. This can disrupt communications between site administrators and members, damage trust in the platform, and expose organizational data loss.

Technical details

The vulnerability is an Insecure Direct Object Reference (IDOR) in the notification deletion endpoint. The pm_delete_notification AJAX action accepts a nonce and notification ID but does not verify that the requesting user is the owner of the target notification. An authenticated attacker with Subscriber role can enumerate notification IDs (sequential integers) and delete notifications belonging to other users, including administrators. The attack requires only a valid WordPress session cookie and nonce; no additional privilege escalation is needed. The vulnerability affects ProfileGrid versions before 5.9.9.8, which is the first patched version.

Affected products

  • ProfileGrid ProfileGrid before 5.9.9.8

Timeline

  • 2026-07-21: disclosed
  • 2026: patched: Fixed in version 5.9.9.8

References

Related threats