Insufficient License Management in ProfileGrid Plugin for WordPress
CVE-2026-12690
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 24 July 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-12690?
The ProfileGrid plugin for WordPress contains a vulnerability related to its license management functionality. This flaw arises from the absence of a proper capability check, as it solely relies on a nonce that is accessible to any logged-in user. Consequently, this allows authenticated users with Subscriber-level access and higher to manipulate the site's premium license settings, potentially leading to unauthorized changes and exploitation of premium features.
Affected Version(s)
ProfileGrid 0 < 5.9.9.7
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.