{"id":"CVE-2026-16291","title":"The ProfileGrid  WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user before deleting it, allowing any authenticated user such as a Subscriber to delete other users' notifications by enumerat…","summary":"The ProfileGrid  WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user before deleting it, allowing any authenticated user such as a Subscriber to delete other users' notifications by enumerat…","severity":"none","published":"2026-08-02","updated":"2026-08-02","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-16291","references":[{"url":"https://wpscan.com/vulnerability/899c2e96-39a9-4e1c-879b-40d6e629e712/","label":"contact@wpscan.com"}],"tags":["nvd"],"ingestedAt":"2026-08-02T13:18:29.621Z","epss":0.00152,"epssPercentile":0.04746,"slug":"CVE-2026-16291","body":"## Overview\n\nThe ProfileGrid  WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user before deleting it, allowing any authenticated user such as a Subscriber to delete other users' notifications by enumerating notification identifiers.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}