Brizy <= 2.6.20 - Missing Authorization to Unauthenticated Limited File Upload

2025-07-28 16:22
mikemyers

Strategic Overview

Status
Patched in 2.6.21
Affected PluginBrizy – Page Builder
Affected Version<= 2.6.20
CVSS5.3Medium
CVECVE-2025-4370
View all Brizy – Page Builder vulnerabilities

Vulnerability Overview

The Brizy – Page Builder plugin for WordPress is vulnerable to limited file uploads due to missing authorization on process_external_asset_urls function as well as missing path validation in store_file function in all versions up to, and including, 2.6.20. This makes it possible for unauthenticated attackers to upload .TXT files on the affected site's server.

Technical Analysis

REMEDIATION: Update to version 2.6.21, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C