Junglewise Threat Intelligence

CVE-2026-24368: ThemeOne The Grid broken access control

CVE-2026-24368 · Severity: medium · CVSS 5.3 · Published 2026-01-22

Executive brief

The Grid is a WordPress plugin used to create and display content grids on websites. A broken access control vulnerability allows unauthenticated users to view pages and perform actions they should not have permission to access, such as viewing other users' private data or performing unauthorized operations.

Technical details

The vulnerability is a broken access control flaw in The Grid WordPress plugin versions up to and including 2.8.0. The plugin fails to properly enforce authorization checks on sensitive operations and pages, allowing unauthenticated users to access restricted functionality and data. The attack requires only network access with no authentication or user interaction needed. An attacker can exploit this to view other users' private content or perform unauthorized actions. The vulnerability has been patched in version 2.8.1.

Affected products

  • ThemeOne The Grid through 2.8.0

Timeline

  • 2026-01-22: disclosed
  • 2026-01-29: patched: Fixed in version 2.8.1

References

Related threats