Executive brief
The Grid is a popular WordPress plugin used to create image galleries and dynamic content displays on websites. A privilege escalation vulnerability allows unauthenticated or low-privilege users to gain administrative access to affected websites, potentially leading to unauthorized content modification, data theft, or malware injection across thousands of sites.
Technical details
The vulnerability stems from incorrect privilege assignment in The Grid WordPress plugin versions through 2.8.0. A low-privilege user (such as a Subscriber) can exploit this flaw to escalate to administrator-level permissions without proper authorization checks. The attack is network-accessible and requires only subscriber-level access, making it exploitable at scale. An attacker gaining admin access can modify site content, install malicious plugins, exfiltrate data, or pivot to compromise hosted infrastructure. A patch is available in version 2.8.1 and later.
Affected products
- ThemeOne The Grid through 2.8.0
Timeline
- 2026-08-18: disclosed
- 2026-08-13: patched: Version 2.8.1 released