CVE-2025-13416: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-13416 is a missing authorization vulnerability in the ProfileGrid – User Profiles, Groups and Communities plugin for WordPress. It allows authenticated attackers with Subscriber-level access or above to suspend arbitrary users (including administrators) from groups without proper authorization checks. All versions up to and including 5.9.7.2 are affected. The vulnerability was published on February 5, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is a missing capability check (CWE-862) on the pm_deactivate_user_from_group() function within the plugin's public-facing class (class-profile-magic-public.php). Because the AJAX action pm_deactivate_user_from_group does not verify whether the requesting user has sufficient privileges, any authenticated user — even one with only Subscriber-level access — can invoke it over the network with no user interaction required. The vulnerable code path is visible in the plugin's source repository at line 3167 of class-profile-magic-public.php (Wordfence, WordPress Trac).

Impact

Successful exploitation allows a low-privileged authenticated attacker to suspend arbitrary users — including site administrators — from ProfileGrid groups, resulting in an integrity impact on group membership management. While confidentiality and availability are not directly affected, the ability to suspend administrators from groups could disrupt community management workflows and potentially be chained with other weaknesses to escalate impact. The scope is limited to the affected WordPress installation (Wordfence).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.026%, indicating a very low probability of exploitation in the near term. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability requires only a valid WordPress account (Subscriber level or above), making it accessible to any registered user on an affected site (Wordfence, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify a WordPress site running the ProfileGrid plugin at version 5.9.7.2 or earlier. This can be done by checking the plugin's readme or version file at /wp-content/plugins/profilegrid-user-profiles-groups-and-communities/readme.txt.
  2. Obtain low-privilege account: Register or log in as a Subscriber-level (or higher) user on the target WordPress site.
  3. Identify target user and group: Determine the user ID of the target (e.g., an administrator) and the group ID from which they should be suspended, using publicly visible profile or group pages.
  4. Craft malicious AJAX request: Send an authenticated HTTP POST request to the WordPress AJAX endpoint (/wp-admin/admin-ajax.php) with the action pm_deactivate_user_from_group and the target user and group IDs as parameters, e.g.:
    POST /wp-admin/admin-ajax.php
    action=pm_deactivate_user_from_group&user_id=<TARGET_USER_ID>&group_id=<GROUP_ID>
  5. Achieve unauthorized suspension: The server processes the request without verifying the requester's privileges, suspending the target user from the specified group (Wordfence, WordPress Trac).

Indicators of compromise

  • Network: Unusual POST requests to /wp-admin/admin-ajax.php with the parameter action=pm_deactivate_user_from_group originating from low-privileged user sessions.
  • Logs: WordPress access logs showing repeated AJAX calls to admin-ajax.php with pm_deactivate_user_from_group from Subscriber-level accounts, especially targeting administrator user IDs.
  • Application: Unexpected group membership changes in ProfileGrid — specifically, administrators or other high-privilege users appearing as suspended in groups without corresponding administrative action.

Mitigation and workarounds

Users should update the ProfileGrid – User Profiles, Groups and Communities plugin to a version beyond 5.9.7.2, which includes the fix adding a proper capability check to the pm_deactivate_user_from_group() function. The patch is available in the WordPress plugin repository changeset. If an immediate update is not possible, site administrators should consider restricting new user registrations or monitoring AJAX logs for suspicious calls to pm_deactivate_user_from_group (Wordfence, WordPress Trac Changeset).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93549HIGH8.8
  • cart-rest-api-for-woocommerce
NoYesOct 04, 2026
CVE-2026-78371MEDIUM5.9
  • woo-addon-uploads
NoYesOct 05, 2026
CVE-2026-13607MEDIUM5.9
  • woo-addon-uploads
NoNoOct 05, 2026
CVE-2026-84169MEDIUM5.3
  • upi-qr-code-payment-gateway
NoNoOct 05, 2026
CVE-2026-97332MEDIUM5.3
  • user-private-files
NoYesOct 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management