CyberRota Analysis
AI-GeneratedThe ProfileGrid WordPress plugin prior to version 5.9.9.8 allows authenticated users, including Subscribers, to delete notifications belonging to other users without proper verification. This vulnerability can lead to unauthorized deletion of notifications, potentially disrupting user communication and privacy. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user before deleting it, allowing any authenticated user such as a Subscriber to delete other users' notifications by enumerating notification identifiers.