SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-14195

LOW · CVSS 2.7 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-01 · Last synced 2026-08-31

CyberRota Analysis

AI-Generated

The Brizy WordPress plugin prior to version 2.8.18 is vulnerable due to inadequate authorization checks, enabling users with Contributor roles or higher to access and read the content of arbitrary posts, including private, pending, and draft posts from other users. This poses a significant privacy risk, as sensitive information may be exposed unintentionally. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data breaches.

CVE
CVE-2026-14195
Severity
LOW
CVSS
2.7
EPSS
0.17%
WordPress

Original NVD Description

The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning post content, allowing users with the Contributor role or higher to read the content of arbitrary posts, including other users' private, pending, and draft posts.