HIGH
Brizy < 1.0.126 - Authorization Bypass to Settings Updates
Published Oct 20, 2023
8.1
HIGHCVSS 3.1
EPSS 0.43%
Description
The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_administrator() function in versions up to, and including, 1.0.125. This makes it possible for authenticated attackers to access and interact with available AJAX functions.
Affected products
-
- Version -StatusaffectedConstraints<1.0.126
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Themefusecom | Brizy – Page Builder | unaffected |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (2)
- https://blog.nintechnet.com/wordpress-brizy-page-builder-plugin-fixed-critical-vulnerabilities/ ExploitThird Party Advisory
- https://www.wordfence.com/threat-intel/vulnerabilities/id/9495e25d-a5a6-4f25-9363-783626e58a4a?source=cve Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://blog.nintechnet.com/wordpress-brizy-page-builder-plugin-fixed-critical-vulnerabilities/ | ExploitThird Party Advisory | |
| https://www.wordfence.com/threat-intel/vulnerabilities/id/9495e25d-a5a6-4f25-9363-783626e58a4a?source=cve | Third Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published Oct 20, 2023
Updated Apr 8, 2026
Reserved Jun 6, 2023
Link CVE-2020-36714
CISA Vulnrichment
Updated Sep 11, 2024