Impact
The vulnerability is a privilege escalation flaw in WordPress The Grid plugin versions 2.7.9.1 and earlier. A subscriber user can leverage this defect to elevate privileges within the WordPress site. The flaw falls under CWE‑266: Improper Privilege Management. The impact includes unauthorized changes to site content, configuration, or granting of additional capabilities to other users. The result is loss of confidentiality, integrity, or availability depending on the actions performed by the compromised account.
Affected Systems
The affected vendor is Theme‑One Inc. and the product is The Grid WordPress plugin. The vulnerability exists in all releases up to and including version 2.7.9.1. Any WordPress installation that has a subscriber account and has this plugin installed within the affected version range is vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. Exploit availability is presently unknown, and the EPSS score is not reported; however the vulnerability is known to be in use by a wide audience of WordPress sites. The vulnerability is not listed in CISA KEV yet. The attack vector is likely remote, requiring an authenticated subscriber account, which can be obtained through standard WordPress registration or other user creation mechanisms. An attacker could exploit the flaw by sending a crafted request to the plugin's endpoints, triggering the privilege escalation. Given the high CVSS rating and the potential for widespread exploitation, administrators should treat this as an urgent risk.
OpenCVE Enrichment