Brizy - Page Builder < 1.0.114 - Missing Authorization to Settings Update
2020-03-05 00:00
riki ajiStrategic Overview
StatusPatched in 1.0.114
Affected PluginBrizy – Page Builder
Affected Version
< 1.0.114CVSS6.5Medium
CVE
N/AVulnerability Overview
The Brizy - Page Builder plugin for WordPress is vulnerable to authorization bypass due to a missing capability check and direct file access to /brizy/admin/site-settings.php in versions up to 1.0.114. This makes it possible for unauthenticated attackers to access the settings page and make modifications to the site's settings. This could be used to inject XSS.
Technical Analysis
REMEDIATION: Update to version 1.0.114, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C