CVE-2021-38345: Brizy <= 1.0.125 and 1.0.127 – 2.3.11 Incorrect authorization checks allowing Post modification
The Brizy Page Builder plugin <= 2.3.11 for WordPress used an incorrect authorization check that allowed any logged-in user accessing any endpoint in the wp-admin directory to modify the content of any existing post or page created with the Brizy editor. An identical issue was found by another researcher in Brizy <= 1.0.125 and fixed in version 1.0.126, but the vulnerability was reintroduced in version 1.0.127.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Brizy Page Builder plugin for WordPressto a version that resolves this vulnerability.Fixed in 1.0.126 - Upgrade
Upgrade
Brizy Page Builder plugin for WordPressto a version that resolves this vulnerability.Fixed in 2.3.11
Event History
Frequently Asked Questions
What is the vulnerability ID of this Brizy Page Builder plugin vulnerability?
The vulnerability ID of this Brizy Page Builder plugin vulnerability is CVE-2021-38345.
What is the severity level of CVE-2021-38345?
The severity level of CVE-2021-38345 is high, with a severity value of 6.5.
How does the vulnerability in the Brizy Page Builder plugin affect WordPress?
The vulnerability in the Brizy Page Builder plugin allows any logged-in user accessing any endpoint in the wp-admin directory to modify the content of any existing post or page created with the Brizy editor.
Which versions of the Brizy Page Builder plugin are affected by CVE-2021-38345?
Versions up to and including 2.3.11 of the Brizy Page Builder plugin are affected by CVE-2021-38345.
Is there a fix available for CVE-2021-38345?
Yes, updating the Brizy Page Builder plugin to a version higher than 2.3.11 will fix CVE-2021-38345.