AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-16070

UNKNOWN · CVSS N/A EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-04

CyberRota Analysis

AI-Generated

The Brizy WordPress plugin prior to version 2.8.19 is vulnerable due to improper authorization verification, allowing users with Contributor-level access and higher to modify the template-type assignment of templates owned by other users. This could lead to unauthorized changes in template configurations, potentially impacting site integrity and user trust. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-16070
Severity
UNKNOWN
CVSS
N/A
EPSS
0.13%
WordPress

Original NVD Description

The Brizy WordPress plugin before 2.8.19 does not properly verify authorization on the object being modified before updating a template's type meta, validating a request parameter that is different from the one used in the write operation, allowing users with Contributor-level access and above to change the template-type assignment of templates owned by other users.