CVE-2026-14195

The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning post content, allowing users with the Contributor role or higher to read the content of arbitrary posts, including other users' private, pending, and draft posts.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-01 07:16

Updated : 2026-08-26 16:31


NVD link : CVE-2026-14195

Mitre link : CVE-2026-14195

CVE.ORG link : CVE-2026-14195


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key