CVE-2020-36714: Brizy < 1.0.126 - Authorization Bypass to Settings Updates
The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the isadministrator() function in versions up to, and including, 1.0.125. This makes it possible for authenticated attackers to access and interact with available AJAX functions.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-36714.
What is the severity of CVE-2020-36714?
The severity of CVE-2020-36714 is high (8.1).
How does CVE-2020-36714 impact the Brizy plugin for WordPress?
CVE-2020-36714 allows authenticated attackers to bypass authorization and access and interact with available AJAX functions in the Brizy plugin for WordPress.
Which versions of the Brizy plugin for WordPress are affected by CVE-2020-36714?
Versions up to and including 1.0.125 of the Brizy plugin for WordPress are affected by CVE-2020-36714.
Are there any fixes or patches available for CVE-2020-36714?
Yes, fixes for CVE-2020-36714 are available in the latest version of the Brizy plugin for WordPress. It is recommended to update to the latest version to mitigate the vulnerability.