Brizy - Page Builder < 1.0.114 - Missing Authorization to Settings Update

2020-03-05 00:00
riki aji

Strategic Overview

Status
Patched in 1.0.114
Affected PluginBrizy – Page Builder
Affected Version< 1.0.114
CVSS6.5Medium
CVEN/A
View all Brizy – Page Builder vulnerabilities

Vulnerability Overview

The Brizy - Page Builder plugin for WordPress is vulnerable to authorization bypass due to a missing capability check and direct file access to /brizy/admin/site-settings.php in versions up to 1.0.114. This makes it possible for unauthenticated attackers to access the settings page and make modifications to the site's settings. This could be used to inject XSS.

Technical Analysis

REMEDIATION: Update to version 1.0.114, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C