CVE-2026-14195

LOW

Brizy – Page Builder < 2.8.18 - Contributor+ Sensitive Information Disclosure via get_post_info

Title source: cna
STIX 2.1

Description

The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning post content, allowing users with the Contributor role or higher to read the content of arbitrary posts, including other users' private, pending, and draft posts.

References (1)

Core 1
Core References
Exploit exploit vdb-entry technical-description
https://wpscan.com/vulnerability/2ed270b0-c01e-4615-b365-3455c161a2d9/

Scores

CVSS v3 2.7
EPSS 0.0018
EPSS Percentile 7.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (1)
None/Brizy < 2.8.18
Published Aug 01, 2026
Tracked Since Aug 01, 2026