PT-2026-57373 · WordPress · Wp Grid Builder

·

CVE-2026-13756

·

Published

2026-07-11

·

Updated

2026-07-11

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP Grid Builder versions prior to 2.3.4
Description An issue exists where missing authorization and meta key validation in the update() handler for the '/wp-json/wpgb/v2/metadata' REST endpoint allows authenticated users with Subscriber-level access or higher to elevate their privileges to Administrator. This is achieved by updating the wp capabilities user meta using a crafted nested array payload.
Recommendations Update WP Grid Builder to version 2.3.4 or later. Restrict access to the '/wp-json/wpgb/v2/metadata' REST endpoint to minimize the risk of exploitation.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13756

Affected Products

Wp Grid Builder