PT-2023-11856 · WordPress · Brizy

Jerome Bruandet

·

Publicado

2023-10-20

·

Atualizado

2025-01-16

·

CVE-2020-36714

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Brizy plugin for WordPress versions up to, and including, 1.0.125
Description The issue is related to an incorrect capability check on the is administrator() function, which allows authenticated attackers to bypass authorization and access available AJAX functions. This enables them to interact with these functions in an unauthorized manner.
Recommendations For versions up to, and including, 1.0.125, update to a version that fixes the incorrect capability check on the is administrator() function to prevent authorization bypass. As a temporary workaround, consider restricting access to available AJAX functions until a patch is available.

Exploit

Correção

Incorrect Authorization

Improper Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2020-36714

Produtos afetados

Brizy