CVE-2026-4609

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the pm_invite_user function in all versions up to, and including, 5.9.8.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to add themselves or any registered user to any ProfileGrid group, including closed and paid groups, bypassing all authorization and payment gates.
Configurations

No configuration.

History

13 May 2026, 14:43

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-13 14:17

Updated : 2026-06-17 10:56


NVD link : CVE-2026-4609

Mitre link : CVE-2026-4609

CVE.ORG link : CVE-2026-4609


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization