CyberRota Analysis
AI-GeneratedThe Brizy WordPress plugin prior to version 2.8.18 is vulnerable due to inadequate authorization checks, enabling users with Contributor roles or higher to access and read the content of arbitrary posts, including private, pending, and draft posts from other users. This poses a significant privacy risk, as sensitive information may be exposed unintentionally. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data breaches.
Original NVD Description
The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning post content, allowing users with the Contributor role or higher to read the content of arbitrary posts, including other users' private, pending, and draft posts.