Cross-Site Scripting Vulnerability in The Grid Plugin by Theme-one
CVE-2026-24370

6.5MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
25 March 2026

What is CVE-2026-24370?

The Grid plugin by Theme-one is susceptible to a cross-site scripting (XSS) vulnerability that can allow attackers to execute arbitrary JavaScript in the context of a user's session. This security flaw affects versions prior to 2.8.0, enabling the potential for stored XSS attacks when malicious payloads are injected via vulnerable input fields. To safeguard against this threat, it is crucial to update to the latest version of The Grid or implement necessary security measures.

Affected Version(s)

The Grid 0 <= 2.8.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phat RiO | Patchstack Bug Bounty Program
.