Description
The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into through its front-end registration, allowing unauthenticated users to register directly into a privileged group and be granted that group's configured role, up to Administrator when such a group exists, leading to privilege escalation.
Published:
2026-07-30
Score:
n/a
EPSS:
n/a
KEV:
No
Impact:
n/a
Action:
n/a
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 30 Jul 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Profilegrid
Profilegrid profilegrid Wordpress Wordpress wordpress |
|
| Vendors & Products |
Profilegrid
Profilegrid profilegrid Wordpress Wordpress wordpress |
Thu, 30 Jul 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into through its front-end registration, allowing unauthenticated users to register directly into a privileged group and be granted that group's configured role, up to Administrator when such a group exists, leading to privilege escalation. | |
| Title | ProfileGrid < 5.9.9.8 - Unauthenticated Privilege Escalation via Unrestricted Group ID | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-07-30T06:00:07.916Z
Reserved: 2026-06-19T08:40:27.925Z
Link: CVE-2026-12687
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-30T08:30:04Z
Weaknesses
No weakness.