Description
Subscriber Privilege Escalation in The Grid <= 2.7.9.1 versions.
Published: 2026-08-18
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a privilege escalation flaw in WordPress The Grid plugin versions 2.7.9.1 and earlier. A subscriber user can leverage this defect to elevate privileges within the WordPress site. The flaw falls under CWE‑266: Improper Privilege Management. The impact includes unauthorized changes to site content, configuration, or granting of additional capabilities to other users. The result is loss of confidentiality, integrity, or availability depending on the actions performed by the compromised account.

Affected Systems

The affected vendor is Theme‑One Inc. and the product is The Grid WordPress plugin. The vulnerability exists in all releases up to and including version 2.7.9.1. Any WordPress installation that has a subscriber account and has this plugin installed within the affected version range is vulnerable.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity. Exploit availability is presently unknown, and the EPSS score is not reported; however the vulnerability is known to be in use by a wide audience of WordPress sites. The vulnerability is not listed in CISA KEV yet. The attack vector is likely remote, requiring an authenticated subscriber account, which can be obtained through standard WordPress registration or other user creation mechanisms. An attacker could exploit the flaw by sending a crafted request to the plugin's endpoints, triggering the privilege escalation. Given the high CVSS rating and the potential for widespread exploitation, administrators should treat this as an urgent risk.

Generated by OpenCVE AI on August 18, 2026 at 15:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade The Grid plugin to version 2.8 or later, which contains a fix for the privilege escalation issue.
  • Remove or disable the plugin on sites where an immediate upgrade is not possible and temporarily limit subscriber roles to prevent exploitation.
  • Review and tighten role permissions for subscriber accounts to limit damage potential while the patch is being applied.
  • Monitor site logs for suspicious activity such as unexpected role changes or unauthorized content edits.

Generated by OpenCVE AI on August 18, 2026 at 15:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Theme-one
Theme-one the Grid
Wordpress
Wordpress wordpress
Vendors & Products Theme-one
Theme-one the Grid
Wordpress
Wordpress wordpress

Tue, 18 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Subscriber Privilege Escalation in The Grid <= 2.7.9.1 versions.
Title WordPress The Grid plugin <= 2.7.9.1 - Privilege Escalation vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Theme-one The Grid
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-18T13:59:00.946Z

Reserved: 2026-02-25T12:14:47.651Z

Link: CVE-2026-28191

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T14:17:02.057

Modified: 2026-08-18T14:17:02.057

Link: CVE-2026-28191

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T15:30:04Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment