Skip to main content

Improper Authorization

CVE-2020-36714

Severity High
Score 7.4/10

Summary

The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_administrator() function in versions up to, and including, 1.0.125. This makes it possible for authenticated attackers to access and interact with available AJAX functions.

  • LOW
  • NETWORK
  • LOW
  • CHANGED
  • NONE
  • LOW
  • LOW
  • LOW

CWE-285 - Improper Authorization

The software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

References

Advisory Timeline

  • Published