CVE-2026-12073 -- CVSS 9.8 Vulnerability Briefing
CVE-2026-12073 | CVSS 9.8 (Critical) | Exploit: No known exploit
What Is It
CVE-2026-12073 is a privilege escalation via account takeover vulnerability affecting the ProfileGrid plugin for WordPress, a plugin used to manage user profiles, groups, and communities, impacting all versions up to and including 5.9.9.5.
Technical Detail
The flaw exists within the ProfileGrid plugin's account management logic, where insufficient validation or authorization controls allow an attacker to take over existing user accounts and escalate privileges. By exploiting this weakness, a low-privileged or unauthenticated attacker may be able to assume control of higher-privileged accounts, including administrator-level accounts, on the affected WordPress installation. The result is full administrative compromise of the WordPress site, enabling arbitrary content modification, credential harvesting, or further lateral movement within the hosting environment.
Exploitation Status
No known exploit has been publicly documented or observed as of July 07, 2026. This vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog. No proof-of-concept code has been confirmed in public repositories at this time, though the critical CVSS score of 9.8 and the nature of the flaw make it a high-priority target for future exploitation attempts.
Who Is Targeting This
No specific threat actor attribution at this time. Neither confirmed nor reported threat actor associations have been established for this vulnerability as of the date of this briefing.
What To Do
WordPress site administrators running ProfileGrid version 5.9.9.5 or earlier should update the plugin to the latest patched release immediately, treating this as a critical priority given the CVSS score of 9.8 and the potential for full site compromise. If an immediate update is not possible, consider deactivating the plugin until patching can be completed, particularly on sites where user registration or community features are exposed to untrusted users. Administrators should audit existing user accounts for unauthorized privilege changes or newly created administrator accounts as an indicator of prior exploitation. Web application firewall rules targeting abnormal account modification or privilege change requests may provide partial mitigation while patching is pending.