CVE-2024-1165: Brizy – Page Builder <= 2.4.39 - Authenticated (Contributor+) Directory Traversal
The Brizy – Page Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.39 via the 'id'. This makes it possible for authenticated attackers, with contributor-level access and above, to upload files to arbitrary locations on the server
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1165?
CVE-2024-1165 is considered a high severity vulnerability due to its potential for authenticated attackers to upload files to arbitrary locations on the server.
How do I fix CVE-2024-1165?
To fix CVE-2024-1165, update the Brizy Page Builder plugin to version 2.4.40 or later.
Who is affected by CVE-2024-1165?
CVE-2024-1165 affects users of the Brizy Page Builder plugin for WordPress up to version 2.4.39 who have contributor-level access or higher.
What kind of attack can be performed using CVE-2024-1165?
Using CVE-2024-1165, authenticated attackers can exploit directory traversal to upload malicious files to arbitrary server locations.
Is there any workaround for CVE-2024-1165?
There are no official workarounds for CVE-2024-1165; the only effective solution is to update to the patched version.