Unauthorized Access Vulnerability in ProfileGrid Plugin for WordPress
CVE-2026-4609
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 May 2026
What is CVE-2026-4609?
The ProfileGrid β User Profiles, Groups and Communities plugin for WordPress has a significant security flaw that allows authenticated users, including those with Subscriber-level access, to exploit a missing capability check on the pm_invite_user function. This vulnerability enables these users to add themselves or any registered user to any ProfileGrid group, including restricted or paid groups, effectively bypassing authorization checks and payment gateways. This poses a serious risk as it undermines the integrity of user group access and can lead to unauthorized content exposure.
Affected Version(s)
ProfileGrid β User Profiles, Groups and Communities 0 <= 5.9.8.4