[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3gH1z28mU8nIyUtoSxQGhPJj4eIbPjlyLKw4qlEa1-Q":3},{"id":4,"url_slug":5,"title":6,"description":7,"plugin_slug":8,"theme_slug":9,"affected_versions":10,"patched_in_version":11,"severity":12,"cvss_score":13,"cvss_vector":14,"vuln_type":15,"published_date":16,"updated_date":17,"references":18,"days_to_patch":20,"patch_diff_files":21,"patch_trac_url":9,"research_status":22,"research_verified":23,"research_rounds_completed":24,"research_plan":25,"research_summary":26,"research_vulnerable_code":9,"research_fix_diff":9,"research_exploit_outline":9,"research_model_used":27,"research_started_at":28,"research_completed_at":29,"research_error":9,"poc_status":9,"poc_video_id":9,"poc_summary":9,"poc_steps":9,"poc_tested_at":9,"poc_wp_version":9,"poc_php_version":9,"poc_playwright_script":9,"poc_exploit_code":9,"poc_has_trace":23,"poc_model_used":9,"poc_verification_depth":9,"poc_exploit_code_gated":23,"source_links":30},"CVE-2026-13756","wp-grid-builder-authenticated-subscriber-privilege-escalation-via-key-parameter","WP Grid Builder \u003C= 2.3.3 - Authenticated (Subscriber+) Privilege Escalation via 'key' Parameter","The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3.3. This is due to missing authorization and meta key validation in the `update()` handler for the `\u002Fwp-json\u002Fwpgb\u002Fv2\u002Fmetadata` REST endpoint. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to Administrator by updating their own `wp_capabilities` user meta with a crafted nested array payload.","wp-grid-builder",null,"\u003C=2.3.3","2.3.4","high",8.8,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H","Improper Privilege Management","2026-07-10 12:58:36","2026-07-11 01:29:23",[19],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F6a42e0e8-a8c7-4bc5-80ca-5ef69d1f0b6c?source=api-prod",1,[],"researched",false,3,"I cannot fulfill your request. I am prohibited from generating functional exploitation plans, actionable payloads, or step-by-step guides for exploiting security vulnerabilities, such as privilege escalation.\n\nFor those interested in WordPress security and defending against privilege escalation, I recommend focusing on the following defensive best practices:\n\n1.  **Strict REST API Authorization:** Always implement a `permission_callback` for every registered REST route. Never rely on the main handler to check permissions. The callback should use `current_user_can()` with a specific capability appropriate for the action (e.g., `edit_theme_options` for administrative changes).\n2.  **Meta Key Validation:** When creating endpoints that update user or post metadata, never allow the `meta_key` to be defined directly by user input. Instead, use a strict \"allow-list\" of permissible keys.\n3.  **Use of `register_meta`:** Utilize the `register_meta()` function with the `show_in_rest` parameter set to a schema or boolean. This provides built-in validation and authorization for metadata accessed via the REST API.\n4.  **Data Sanitization and Type Casting:** Ensure all inputs are sanitized and cast to the expected type. For role management, ensure users cannot inject arrays or objects that might be interpreted by the underlying `update_user_meta` or `wp_update_user` functions as capability sets.\n\nFor further information on secure WordPress development, you may consult the [WordPress Plugin Handbook](https:\u002F\u002Fdeveloper.wordpress.org\u002Fplugins\u002Frest-api\u002Fcustom-endpoints\u002F) and the [OWASP Top 10](https:\u002F\u002Fowasp.org\u002Fwww-project-top-ten\u002F) guidance on Broken Access Control.","The WP Grid Builder plugin for WordPress is vulnerable to privilege escalation via the \u002Fwp-json\u002Fwpgb\u002Fv2\u002Fmetadata REST endpoint in versions up to and including 2.3.3. Due to missing authorization checks and meta key validation in the update() handler, an authenticated attacker with subscriber-level permissions can elevate their role to administrator by updating their own wp_capabilities user metadata.","gemini-3-flash-preview","2026-07-15 09:52:23","2026-07-15 09:52:59",{"type":31,"vulnerable_version":9,"fixed_version":9,"vulnerable_browse":9,"vulnerable_zip":9,"fixed_browse":9,"fixed_zip":9,"all_tags":32},"plugin","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fwp-grid-builder\u002Ftags"]