Cross-Site Scripting Vulnerability in The Grid Plugin by Theme-one
CVE-2026-24370
6.5MEDIUM
What is CVE-2026-24370?
The Grid plugin by Theme-one is susceptible to a cross-site scripting (XSS) vulnerability that can allow attackers to execute arbitrary JavaScript in the context of a user's session. This security flaw affects versions prior to 2.8.0, enabling the potential for stored XSS attacks when malicious payloads are injected via vulnerable input fields. To safeguard against this threat, it is crucial to update to the latest version of The Grid or implement necessary security measures.
Affected Version(s)
The Grid 0 <= 2.8.0