Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeOne The Grid allows Stored XSS.

This issue affects The Grid: from n/a through 2.8.0.
Published: 2026-03-25
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of user input in the WordPress The Grid plugin allows malicious code to be stored within the site’s content. When a user views that content, the script runs in their browser, enabling attackers to steal credentials, hijack sessions or deface the site. The flaw is a classic input validation failure and does not provide direct server‑side code execution, but it can undermine the confidentiality and integrity of all users who visit affected pages.

Affected Systems

The Grid plugin, released by ThemeOne, is affected in all versions up to and including 2.8.0. Any WordPress site that has installed a version dated prior to 2.8.1 and has not upgraded is vulnerable, regardless of how many WordPress installations or user roles are present.

Risk and Exploitability

The CVSS score of 6.5 places this vulnerability in the moderate severity range. The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, so no widespread attacks have been reported. The most likely attack vector is remote via the web: an attacker with the ability to submit content through the plugin’s administrative interface can inject malicious scripts that are then served to any site visitor. The stored nature of the flaw means that a single successful injection can impact all users who view the affected content, making the risk significant for high‑traffic sites.

Generated by OpenCVE AI on September 2, 2026 at 00:25 UTC.

Remediation

Vendor Solution

Update the WordPress The Grid plugin to the latest available version (at least 2.8.1).


OpenCVE Recommended Actions

  • Upgrade The Grid plugin to version 2.8.1 or later as recommended by the vendor
  • If the plugin is not required for site functionality, disable or uninstall it to eliminate the attack surface
  • Perform a content audit to remove any injected scripts and clear cached pages to ensure no remnants of malicious code remain

Generated by OpenCVE AI on September 2, 2026 at 00:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:30:00 +0000


Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme-one The Grid the-grid allows Stored XSS.This issue affects The Grid: from n/a through < 2.8.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeOne The Grid allows Stored XSS. This issue affects The Grid: from n/a through 2.8.0.
Title WordPress The Grid plugin < 2.8.0 - Cross Site Scripting (XSS) vulnerability WordPress The Grid plugin <= 2.8.0 - Cross Site Scripting (XSS) vulnerability
References

Thu, 26 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Theme-one
Theme-one the Grid
Wordpress
Wordpress wordpress
Vendors & Products Theme-one
Theme-one the Grid
Wordpress
Wordpress wordpress

Wed, 25 Mar 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 25 Mar 2026 16:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme-one The Grid the-grid allows Stored XSS.This issue affects The Grid: from n/a through < 2.8.0.
Title WordPress The Grid plugin < 2.8.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Theme-one The Grid
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-01T21:35:36.980Z

Reserved: 2026-01-22T14:42:32.873Z

Link: CVE-2026-24370

cve-icon Vulnrichment

Updated: 2026-03-25T20:23:09.748Z

cve-icon NVD

Status : Deferred

Published: 2026-03-25T17:16:37.527

Modified: 2026-09-01T22:17:11.157

Link: CVE-2026-24370

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T00:30:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')