PT-2021-22065 · WordPress+1 · Brizy – Page Builder+1
Ramuel Gall
·
Published
2021-10-14
·
Updated
2022-10-27
·
CVE-2021-38345
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Brizy Page Builder plugin versions 2.3.11 and earlier
Brizy versions 1.0.127 and earlier, excluding version 1.0.126
Description
The Brizy Page Builder plugin for WordPress used an incorrect authorization check, allowing any logged-in user accessing any endpoint in the wp-admin directory to modify the content of any existing post or page created with the Brizy editor. This issue was previously found and fixed in Brizy version 1.0.126 but was reintroduced in version 1.0.127.
Recommendations
For Brizy Page Builder plugin versions 2.3.11 and earlier, update to a version later than 2.3.11 to resolve the issue.
For Brizy versions 1.0.127 and earlier, excluding version 1.0.126, update to version 1.0.126 or later to fix the vulnerability.
As a temporary workaround, consider restricting access to the wp-admin directory to minimize the risk of exploitation.
Fix
Incorrect Authorization
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Brizy
Brizy – Page Builder