Mehrere Schwachstellen (CVE-2026-11387, CVE-2026-12073, CVE-2026-6070) in Wordpress
WordPress - Profilegrid – User Profiles, Groups And Communities - CRITICAL - CVE-2026-12073.
The ProfileGrid - User Profiles, Groups and Communities plugin for WordPress contains a vulnerability that allows unauthenticated attackers to exploit a lack of user login validation during registration. This oversight enables attackers to manipulate error messages and hijack the email account linked to the user ID=1 (typically the administrator). By doing so, they can reset the administrator's password and gain unauthorized access to the admin account, potentially compromising the entire website.
Quelle: securityvulnerability.io