What the vulnerability does
01Description
Missing Authorization vulnerability in Theme-one The Grid the-grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Grid: from n/a through < 2.8.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
What the vulnerability does
Missing Authorization vulnerability in Theme-one The Grid the-grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Grid: from n/a through < 2.8.0.
Explanation of Vulnerability in Simple Terms
The Grid theme for WordPress contains an authorization flaw that allows authenticated users with low privileges to modify site content and disrupt availability. The vulnerability affects versions up to 2.8.0. An attacker with a basic user account can bypass permission checks to alter data or cause the site to become unavailable. Site administrators should update immediately to a patched version.
What an attacker can do
Modify site content and cause the site to become unavailable or unstable.
Potential impact on your site
Unauthorized users can alter your site's content and cause service disruptions without admin approval.
Conditions required to exploit
Attacker needs a low-privilege user account (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities