PT-2026-67658 · WordPress · Brizy

CVE-2026-16070

·

Published

2026-08-04

·

Updated

2026-08-04

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Brizy WordPress plugin versions prior to 2.8.19
Description An Insecure Direct Object Reference (IDOR) exists where the software fails to properly verify authorization on the object being modified before updating a template's type meta. The system validates a request parameter that differs from the one used in the write operation, enabling users with Contributor-level access and above to change the template-type assignment of templates owned by other users.
Recommendations Update the plugin to version 2.8.19 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16070

Affected Products

Brizy