Privilege Escalation Vulnerability in WP Grid Builder Plugin for WordPress
CVE-2026-13756

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
11 July 2026

What is CVE-2026-13756?

The WP Grid Builder plugin for WordPress has a Privilege Escalation vulnerability present in all versions up to 2.3.3. This arises from inadequate authorization and meta key validation within the update() handler of the /wp-json/wpgb/v2/metadata REST endpoint. As a result, authenticated attackers with at least Subscriber-level permissions can exploit this flaw to modify their wp_capabilities user meta using a specially crafted nested array payload, thereby gaining unauthorized Administrator privileges.

Affected Version(s)

WP Grid Builder 0 <= 2.3.3

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

h0xilo
.