CVE Database
/

CVE-2021-38345

Back to search

CVE-2021-38345

Published: Oct 14, 2021

Modified: Feb 14, 2025

PUBLISHED

CVSS v3.1

7.1

HIGH

Description

The Brizy Page Builder plugin <= 2.3.11 for WordPress used an incorrect authorization check that allowed any logged-in user accessing any endpoint in the wp-admin directory to modify the content of any existing post or page created with the Brizy editor. An identical issue was found by another researcher in Brizy <= 1.0.125 and fixed in version 1.0.126, but the vulnerability was reintroduced in version 1.0.127.

VendorProductVersions

Brizy.io

Brizy - Page Builder

affected
2.3.11 - <= 2.3.11
affected
1.0.127 - < 1.0.127*
affected
1.0.125 - <= 1.0.125

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L

Attack Vector

Network

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

High

Availability

Low

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now