Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.8
CVE-2026-13756: WP Grid Builder <= 2.3.3: Elevated Privileges for Subscribers
CVE-2026-13756
CVE-2026-13756
Summary
The WP Grid Builder plugin for WordPress allows attackers with Subscriber-level access to gain Administrator privileges. This is a serious security risk, as it could allow unauthorized users to make changes to the website. To protect your site, update the plugin to a version higher than 2.3.3.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| wp grid builder | wp grid builder | <= 2.3.3 |
Original title
WP Grid Builder <= 2.3.3 - Authenticated (Subscriber+) Privilege Escalation via 'key' Parameter
Original description
The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3.3. This is due to missing authorization and meta key validation in the `update()` handler for the `/wp-json/wpgb/v2/metadata` REST endpoint. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to Administrator by updating their own `wp_capabilities` user meta with a crafted nested array payload.
nvd CVSS3.1
8.8
Vulnerability type
CWE-269
Improper Privilege Management
Published: 11 Jul 2026 · Updated: 20 Jul 2026 · First seen: 11 Jul 2026