CVE-2020-36714
20.10.2023, 08:15
The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_administrator() function in versions up to, and including, 1.0.125. This makes it possible for authenticated attackers to access and interact with available AJAX functions.Enginsight
Vendor | Product | Version |
---|---|---|
brizy | brizy | 𝑥 ≤ 1.0.125 |
𝑥
= Vulnerable software versions
References