CVE-2024-3711: Brizy – Page Builder <= 2.4.43 - Missing Authorization
The Brizy – Page Builder plugin for WordPress is vulnerable to unauthorized plugin setting update due to a missing capability check on the functions actionrequestdisable, actionchangetemplate, and actionrequestenable in all versions up to, and including, 2.4.43. This makes it possible for authenticated attackers, with contributor access or above, to enable/disable the Brizy editor and modify the template used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3711?
CVE-2024-3711 has a medium severity due to potential unauthorized access to plugin settings.
How do I fix CVE-2024-3711?
To fix CVE-2024-3711, update the Brizy Page Builder plugin to version 2.4.44 or later.
What versions of Brizy Page Builder are affected by CVE-2024-3711?
All versions of Brizy Page Builder up to and including 2.4.43 are affected by CVE-2024-3711.
What kind of vulnerability is CVE-2024-3711?
CVE-2024-3711 is a vulnerability that allows unauthorized users to update plugin settings.
What actions can be abused in CVE-2024-3711?
The actions that can be abused in CVE-2024-3711 include action_request_disable, action_change_template, and action_request_enable.