Authorization Bypass in ProfileGrid User Profiles Plugin for WordPress
CVE-2026-4607
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 May 2026
What is CVE-2026-4607?
The ProfileGrid β User Profiles, Groups and Communities plugin for WordPress contains an authorization bypass vulnerability that affects all versions up to and including 5.9.8.4. This vulnerability arises from the failure of the plugin to adequately verify user authorizations when performing certain actions through AJAX calls, specifically pm_set_group_order, pm_set_group_items, and pm_set_field_order. As a result, authenticated users, holding a Subscriber-level role or above, can gain unauthorized access to modify crucial group settings such as the order of menu items, group display options, and field arrangements, thereby compromising the overall integrity and security of the affected WordPress sites.
Affected Version(s)
ProfileGrid β User Profiles, Groups and Communities 0 <= 5.9.8.4