Impact
The Grid plugin suffers a missing authorization flaw that allows exploitation of incorrectly configured access control settings. This breaks the expected security boundaries, letting attackers gain unauthorized access or modify content that should be restricted. The weakness is categorized as CWE‑862.
Affected Systems
All WordPress installations that use ThemeOne The Grid plugin up to version 2.8.0 are vulnerable. The plugin’s affected range spans from its first release through any version prior to 2.8.0, regardless of the underlying WordPress version.
Risk and Exploitability
The CVSS score of 7.1 indicates medium‑high severity, while the EPSS score of less than 1% suggests exploitation is currently unlikely. The vulnerability is not listed in CISA’s KEV catalog and no public exploits are documented. The likely attack vector is inferred from the missing authorization description: attackers can execute privileged operations by sending authenticated requests to the plugin’s API endpoints, which may be accessible to any user role that receives elevated capabilities.
OpenCVE Enrichment