Privilege Escalation in ProfileGrid Plugin for WordPress
CVE-2026-12073
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 30 June 2026
What is CVE-2026-12073?
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress contains a vulnerability that allows unauthenticated attackers to exploit a lack of user login validation during registration. This oversight enables attackers to manipulate error messages and hijack the email account linked to the user ID=1 (typically the administrator). By doing so, they can reset the administrator's password and gain unauthorized access to the admin account, potentially compromising the entire website.
Affected Version(s)
ProfileGrid β User Profiles, Groups and Communities 0 <= 5.9.9.5