Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme-one The Grid the-grid allows Stored XSS.This issue affects The Grid: from n/a through < 2.8.0.
Published: 2026-03-25
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored XSS
Action: Immediate Patch
AI Analysis

Impact

Improper neutralization of user input leads to stored cross‑site scripting in the WordPress "The Grid" plugin. Malicious code can be inserted through plugin input fields and later executed in the browsers of any user who views the affected content, potentially allowing credential theft, session hijacking, or defacement. The weakness is a classic example of input validation failure. The impact is limited to sites running the vulnerable plugin, but it can affect any visitor to the site, compromising confidentiality and integrity of user sessions. The vulnerability does not grant arbitrary code execution on the server, but it can influence user interactions and data. The CVE description explicitly states a stored XSS flaw.

Affected Systems

The Grid plugin by Theme‑one, a WordPress content‑grid solution. All releases with a version less than 2.8.0 are affected, as the issue applies to "n/a through < 2.8.0". Users of the plugin in any environment should verify whether they have an older version. No newer versions have been identified as vulnerable.

Risk and Exploitability

The CVSS score of 6.5 places the flaw in the moderate range. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation yet. The likely attack vector is remote via the web, with an attacker injecting code into content that is later served to other users. Exploitation requires only that the site owner fails to mitigate the input, and it does not need authenticated access. Because the flaw is stored, a single upload or content edit by an attacker can affect all users who view that content, making the risk significant for sites with many visitors.

Generated by OpenCVE AI on March 25, 2026 at 22:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update The Grid plugin to version 2.8.0 or later.

Generated by OpenCVE AI on March 25, 2026 at 22:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 26 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Theme-one
Theme-one the Grid
Wordpress
Wordpress wordpress
Vendors & Products Theme-one
Theme-one the Grid
Wordpress
Wordpress wordpress

Wed, 25 Mar 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 25 Mar 2026 16:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme-one The Grid the-grid allows Stored XSS.This issue affects The Grid: from n/a through < 2.8.0.
Title WordPress The Grid plugin < 2.8.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Theme-one The Grid
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-24T15:35:43.756Z

Reserved: 2026-01-22T14:42:32.873Z

Link: CVE-2026-24370

cve-icon Vulnrichment

Updated: 2026-03-25T20:23:09.748Z

cve-icon NVD

Status : Deferred

Published: 2026-03-25T17:16:37.527

Modified: 2026-04-24T16:32:53.997

Link: CVE-2026-24370

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-26T12:13:10Z

Weaknesses