Impact
Improper neutralization of user input in the WordPress The Grid plugin allows malicious code to be stored within the site’s content. When a user views that content, the script runs in their browser, enabling attackers to steal credentials, hijack sessions or deface the site. The flaw is a classic input validation failure and does not provide direct server‑side code execution, but it can undermine the confidentiality and integrity of all users who visit affected pages.
Affected Systems
The Grid plugin, released by ThemeOne, is affected in all versions up to and including 2.8.0. Any WordPress site that has installed a version dated prior to 2.8.1 and has not upgraded is vulnerable, regardless of how many WordPress installations or user roles are present.
Risk and Exploitability
The CVSS score of 6.5 places this vulnerability in the moderate severity range. The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, so no widespread attacks have been reported. The most likely attack vector is remote via the web: an attacker with the ability to submit content through the plugin’s administrative interface can inject malicious scripts that are then served to any site visitor. The stored nature of the flaw means that a single successful injection can impact all users who view the affected content, making the risk significant for high‑traffic sites.
OpenCVE Enrichment