PT-2026-67037 · WordPress · Brizy
CVSS v3.1
2.7
Low
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Brizy WordPress plugin versions prior to 2.8.18
Description
Insufficient authorization verification in a request handler allows users with the Contributor role or higher to access the content of arbitrary posts. This includes the ability to read private, pending, and draft posts belonging to other users via the
get post info function.Recommendations
Update the Brizy WordPress plugin to version 2.8.18 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Brizy