Junglewise Threat Intelligence

CVE-2026-49054: Mamunur Rashid The Post Grid missing authorization

CVE-2026-49054 · Severity: medium · CVSS 4.3 · Published 2026-05-27

Vendors: RadiusTheme.

Executive brief

The Post Grid, a WordPress plugin used to display blog posts and content in various layouts, contains a security flaw in its access control settings. This vulnerability allows logged-in users with low-level permissions (such as Contributors) to bypass intended security restrictions. While the impact is considered low, it could lead to unauthorized access to certain plugin features or data that should be restricted to administrators.

Technical details

A Missing Authorization (CWE-862) vulnerability exists in the Mamunur Rashid The Post Grid plugin for WordPress through version 7.9.2. The flaw stems from insufficient validation of user permissions when accessing certain plugin functions or settings. An attacker authenticated with 'Contributor' level privileges can exploit this to bypass intended access control security levels. This could allow for unauthorized information disclosure or the execution of restricted actions. As of the advisory date, no official patch has been confirmed, and users are advised to monitor for updates from the developer.

Affected products

  • Mamunur Rashid The Post Grid up to 7.9.2

Timeline

  • 2026-02-21: other: Vulnerability reported by researcher
  • 2026-05-27: disclosed: Public disclosure of the vulnerability
  • 2026-05-27: advisory: NVD and Patchstack advisories published

References