Description
Incorrect Privilege Assignment vulnerability in ThemeOne The Grid allows Privilege Escalation.

This issue affects The Grid: from n/a through 2.8.0.
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an incorrect privilege assignment flaw in the ThemeOne The Grid WordPress plugin versions 2.8.0 and earlier. A subscriber user can exploit this defect to elevate their privileges within the WordPress site. The flaw falls under CWE‑266: Improper Privilege Management. The impact includes unauthorized changes to site content, configuration, or the granting of additional capabilities to other users. The result is loss of confidentiality, integrity, or availability depending on the actions performed by the compromised account.

Affected Systems

The affected vendor is Theme‑One Inc. and the product is The Grid WordPress plugin. The vulnerability exists in all releases up to and including version 2.8.0. Any WordPress installation that has a subscriber account and has this plugin installed within the affected version range is vulnerable.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity. Exploit availability is presently unknown, but the EPSS score indicates a very low probability of exploitation at 0.00306 (less than 1%). The vulnerability is not listed in CISA KEV. The attack vector is likely remote, requiring an authenticated subscriber account, which can be obtained through standard WordPress registration or other user creation mechanisms. An attacker could exploit the flaw by sending a crafted request to the plugin's endpoints, triggering the privilege escalation. Given the high CVSS rating and the potential for widespread exploitation, administrators should treat this as an urgent risk.

Generated by OpenCVE AI on September 1, 2026 at 18:24 UTC.

Remediation

Vendor Solution

Update the WordPress The Grid plugin to the latest available version (at least 2.8.1).


OpenCVE Recommended Actions

  • Upgrade the WordPress The Grid plugin to version 2.8.1 or later, which contains the fix for the privilege escalation issue.
  • Remove or disable the plugin on sites where an immediate upgrade is not possible and temporarily limit subscriber roles to prevent exploitation.
  • Review and tighten role permissions for subscriber accounts to limit damage potential while the patch is being applied.
  • Monitor site logs for suspicious activity such as unexpected role changes or unauthorized content edits.

Generated by OpenCVE AI on September 1, 2026 at 18:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Subscriber Privilege Escalation in The Grid <= 2.7.9.1 versions. Incorrect Privilege Assignment vulnerability in ThemeOne The Grid allows Privilege Escalation. This issue affects The Grid: from n/a through 2.8.0.
Title WordPress The Grid plugin <= 2.7.9.1 - Privilege Escalation vulnerability WordPress The Grid plugin <= 2.8.0 - Privilege Escalation vulnerability

Tue, 18 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Theme-one
Theme-one the Grid
Wordpress
Wordpress wordpress
Vendors & Products Theme-one
Theme-one the Grid
Wordpress
Wordpress wordpress

Tue, 18 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Subscriber Privilege Escalation in The Grid <= 2.7.9.1 versions.
Title WordPress The Grid plugin <= 2.7.9.1 - Privilege Escalation vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Theme-one The Grid
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-01T14:41:15.534Z

Reserved: 2026-02-25T12:14:47.651Z

Link: CVE-2026-28191

cve-icon Vulnrichment

Updated: 2026-08-18T19:40:36.997Z

cve-icon NVD

Status : Deferred

Published: 2026-08-18T14:17:02.057

Modified: 2026-09-01T15:17:14.200

Link: CVE-2026-28191

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T18:30:06Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment