Description
The Brizy – Page Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.39 via the 'id'. This makes it possible for authenticated attackers, with contributor-level access and above, to upload files to arbitrary locations on the server
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-16933 | The Brizy – Page Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.39 via the 'id'. This makes it possible for authenticated attackers, with contributor-level access and above, to upload files to arbitrary locations on the server |
References
History
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Brizy – Page Builder <= 2.4.39 - Authenticated (Contributor+) Directory Traversal |
Wed, 25 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 16 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Brizy
Brizy brizy |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:brizy:brizy:*:*:*:*:free:wordpress:*:* | |
| Vendors & Products |
Brizy
Brizy brizy |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:01:31.147Z
Reserved: 2024-02-01T17:35:27.208Z
Link: CVE-2024-1165
Updated: 2024-08-01T18:33:25.100Z
Status : Modified
Published: 2024-02-26T16:27:51.880
Modified: 2026-04-08T18:20:28.813
Link: CVE-2024-1165
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD