CyberRota
← Ana sayfaya dön

CVE-2026-12689

MEDIUM · CVSS 5.4 EPSS %0.13

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-07-24T07:16:32.580 · Çekilme zamanı: 2026-07-25T06:06:28.665249+00:00

CyberRota Yorumu

Saldırganın giriş yapmış olması gerekebilir.

CVE
CVE-2026-12689
Severity
MEDIUM
CVSS
5.4
EPSS
%0.13
WordPress

Orijinal NVD Açıklaması

The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions, allowing authenticated users with Subscriber-level access and above to soft-delete, tamper with the metadata of, and mark as read other users' private message threads.