CVE-2025-26902: WordPress Brizy Pro plugin <= 2.8.0 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Brizy Brizy Pro allows Cross Site Request Forgery.This issue affects Brizy Pro: from n/a through 2.6.1.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in Brizy Brizy Pro brizy-pro allows Cross Site Request Forgery.This issue affects Brizy Pro: from n/a through <= 2.8.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26902?
CVE-2025-26902 is classified as a Cross-Site Request Forgery (CSRF) vulnerability in Brizy Pro.
How do I fix CVE-2025-26902?
To fix CVE-2025-26902, ensure that you update Brizy Pro to version 2.6.2 or later.
What versions of Brizy Pro are affected by CVE-2025-26902?
CVE-2025-26902 affects Brizy Pro versions up to and including 2.6.1.
Can CVE-2025-26902 allow unauthorized actions?
Yes, CVE-2025-26902 allows attackers to perform unauthorized actions on behalf of a user without their consent.
Is there a workaround for CVE-2025-26902?
The recommended solution for CVE-2025-26902 is to update to the latest version of Brizy Pro, as no temporary workaround is suggested.