CVE-2025-26901: WordPress Brizy Pro plugin <= 2.8.0 - Broken Access Control vulnerability
Missing Authorization vulnerability in Brizy Brizy Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Brizy Pro: from n/a through 2.6.1.
Other sources
Missing Authorization vulnerability in Brizy Brizy Pro brizy-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Brizy Pro: from n/a through <= 2.8.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26901?
CVE-2025-26901 is classified as a missing authorization vulnerability, which can lead to unauthorized access in Brizy Pro.
How do I fix CVE-2025-26901?
To fix CVE-2025-26901, upgrade Brizy Pro to the latest version above 2.6.1 where the issue is addressed.
What are the consequences of CVE-2025-26901?
Exploiting CVE-2025-26901 can allow attackers to bypass access control measures and gain unauthorized access to sensitive information.
Who is affected by CVE-2025-26901?
CVE-2025-26901 affects users of Brizy Pro versions from n/a to 2.6.1.
Is CVE-2025-26901 a common vulnerability?
While the prevalence of CVE-2025-26901 is not specified, missing authorization flaws are commonly exploited in web applications.