CVE-2026-12689
EUVD-2026-4849024.07.2026, 07:16
The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions, allowing authenticated users with Subscriber-level access and above to soft-delete, tamper with the metadata of, and mark as read other users' private message threads.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.