CVE-2026-14195: Brizy – Page Builder < 2.8.18 - Contributor+ Sensitive Information Disclosure via get_post_info
Published Aug 1, 2026
·Updated
The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning post content, allowing users with the Contributor role or higher to read the content of arbitrary posts, including other users' private, pending, and draft posts.
Affected Software
1 affected component
Brizy Brizy – Page Builder (WordPress plugin)<2.8.18
Event History
Aug 1, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:16 AM
Description