blog.nintechnet.com
https://blog.nintechnet.com/wordpress-brizy-page-builder-plugin-fixed-critical-vulnerabilities CVE-2020-36714
HIGH
Brizy < 1.0.126 - Authorization Bypass to Settings Updates
Record summary
CVE-2020-36714 has a selected CVSS score of 7.4 (high).
Description
The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_administrator() function in versions up to, and including, 1.0.125. This makes it possible for authenticated attackers to access and interact with available AJAX functions.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 3, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 11, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
brizyBrowse brizy / brizy | VulnCheck | Version data not supplied | |
Brizy – Page BuilderBrowse themefusecom / Brizy – Page BuilderDefault status: unaffected | CVE List | Before 1.0.126 | affected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-36714 wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/9495e25d-a5a6-4f25-9363-783626e58a4a?source=cve