
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-16291 is an Insecure Direct Object Reference (IDOR) vulnerability in the ProfileGrid WordPress plugin (by Metagauss) that allows any authenticated user with at least Subscriber-level access to delete other users' notifications by enumerating notification identifiers. All versions of the plugin before 5.9.9.8 are affected. The vulnerability was publicly disclosed on July 21, 2026, and added to NVD on August 2, 2026. It carries a CVSS score of 4.3 (Medium) (WPScan, Github Advisory).
The root cause is a missing authorization check (CWE-639: Authorization Through User-Controlled Key) when processing notification deletion requests. The plugin fails to verify that the notification ID supplied in the request belongs to the authenticated user making the request, enabling any logged-in user to supply arbitrary notification IDs and delete notifications owned by other accounts. This is a classic IDOR (Insecure Direct Object Reference) pattern, classified under OWASP Top 10 A5: Broken Access Control. A proof-of-concept is expected to be published by WPScan on August 4, 2026, to allow time for users to update (WPScan).
Successful exploitation allows any authenticated user — including those with the lowest-privilege Subscriber role — to permanently delete notifications belonging to any other user on the WordPress site by iterating through notification identifiers. This results in an integrity impact through unauthorized data deletion and may disrupt user experience or hide important system or administrative notifications. The vulnerability does not directly enable data exfiltration, privilege escalation, or remote code execution, limiting its scope to notification data integrity (WPScan, Github Advisory).
Update the ProfileGrid WordPress plugin to version 5.9.9.8 or later, which introduces proper ownership verification before processing notification deletion requests. No configuration-based workaround is available; upgrading is the only effective remediation. Site administrators should also review user accounts for any unauthorized Subscriber-level registrations that could be used to exploit this or similar vulnerabilities (WPScan, Github Advisory).
The vulnerability was discovered and reported by independent researcher Meher Sudhakar Abbireddi and verified by WPScan. No significant broader media coverage or notable community commentary beyond standard vulnerability database aggregation has been observed at this time (WPScan).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."