Privilege Escalation Vulnerability in WP Grid Builder Plugin for WordPress
CVE-2026-13756
8.8HIGH
What is CVE-2026-13756?
The WP Grid Builder plugin for WordPress has a Privilege Escalation vulnerability present in all versions up to 2.3.3. This arises from inadequate authorization and meta key validation within the update() handler of the /wp-json/wpgb/v2/metadata REST endpoint. As a result, authenticated attackers with at least Subscriber-level permissions can exploit this flaw to modify their wp_capabilities user meta using a specially crafted nested array payload, thereby gaining unauthorized Administrator privileges.
Affected Version(s)
WP Grid Builder 0 <= 2.3.3