PT-2023-11856 · WordPress · Brizy

Jerome Bruandet

·

Published

2023-10-20

·

Updated

2025-01-16

·

CVE-2020-36714

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Brizy plugin for WordPress versions up to, and including, 1.0.125
Description The issue is related to an incorrect capability check on the is administrator() function, which allows authenticated attackers to bypass authorization and access available AJAX functions. This enables them to interact with these functions in an unauthorized manner.
Recommendations For versions up to, and including, 1.0.125, update to a version that fixes the incorrect capability check on the is administrator() function to prevent authorization bypass. As a temporary workaround, consider restricting access to available AJAX functions until a patch is available.

Exploit

Fix

Incorrect Authorization

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2020-36714

Affected Products

Brizy