Impact
CVE-2026-16070 exposes an authorization bypass in the Brizy WordPress plugin. The plugin fails to verify that the user modifying a template owns the template, instead comparing a request parameter unrelated to the write operation. Users with Contributor-level or higher privileges can therefore alter the template-type metadata of templates belonging to other users. This allows unauthorized manipulation of site layouts and could facilitate further privilege escalation.
Affected Systems
All WordPress installations running Brizy Page Builder before version 2.8.19 are affected. The flaw applies to sites that have users assigned the Contributor role or higher, regardless of the WordPress core version. No other plugins or components are mentioned. The impact is confined to the Brizy plugin’s template management interface.
Risk and Exploitability
The vulnerability has a CVSS score of 2.7 and an EPSS score of < 1%, indicating a relatively low exploitation probability. Based on the description, it is inferred that an attacker can modify template-type metadata as any authenticated user with Contributor or higher privileges. Because privilege escalation is straightforward once a contributor account exists, the risk for sites that expose this role widely is inferred to be high. No public exploit or KEV listing is documented, but the broad attack surface and simple exploitation path are inferred to warrant immediate attention. The potential for cascading effects is inferred, justifying a high priority for remediation.
OpenCVE Enrichment