SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-12687

HIGH · CVSS 7.5 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The ProfileGrid WordPress plugin prior to version 5.9.9.8 is vulnerable due to insufficient restrictions on group registration for anonymous users, enabling them to register into privileged groups and potentially gain roles up to Administrator. This flaw poses a significant risk of privilege escalation, allowing unauthorized access to sensitive administrative functions. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this security risk.

CVE
CVE-2026-12687
Severity
HIGH
CVSS
7.5
EPSS
0.30%
WordPress

Original NVD Description

The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into through its front-end registration, allowing unauthenticated users to register directly into a privileged group and be granted that group's configured role, up to Administrator when such a group exists, leading to privilege escalation.