Junglewise Threat Intelligence

CVE-2026-13756: WP Grid Builder privilege escalation in metadata REST endpoint

CVE-2026-13756 · Severity: high · CVSS 8.8 · Published 2026-07-11

Executive brief

WP Grid Builder, a WordPress plugin used to create advanced grid layouts and filtering systems, contains a security flaw that allows users with low-level accounts (such as subscribers) to grant themselves full administrative control. By exploiting a weakness in how the plugin handles user metadata, an attacker can take over the entire website, potentially leading to data theft, site defacement, or complete service disruption. This issue affects all versions of the plugin up to 2.3.3 and has been fixed in version 2.3.4.

Technical details

The WP Grid Builder plugin for WordPress suffers from an improper privilege management vulnerability (CWE-269) within its REST API implementation. Specifically, the `update()` handler for the `/wp-json/wpgb/v2/metadata` endpoint lacks sufficient authorization checks and fails to validate meta keys. This allows an authenticated attacker, even with low-level Subscriber permissions, to modify their own `wp_capabilities` user meta. By submitting a crafted nested array payload to this endpoint, an attacker can overwrite their account permissions to gain full Administrator access. The vulnerability is resolved in version 2.3.4.

Affected products

  • WP Grid Builder WP Grid Builder 0 - 2.3.3

Timeline

  • 2026-07-01: patched: Version 2.3.4 released fixing the metadata REST endpoint issue.
  • 2026-07-11: advisory: CVE-2026-13756 published.

References