Back to CVE List

CVE-2026-12687

Vulnerability Description

The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into through its front-end registration, allowing unauthenticated users to register directly into a privileged group and be granted that group's configured role, up to Administrator when such a group exists, leading to privilege escalation.

Vulnerability Details

Published Date
Last Modified
Source
NVD
Vendor
Unknown
Product
ProfileGrid

External References

Discussion (0)

Add Comment

No comments yet. Be the first!