Impact
CVE-2026-16070 exposes an authorization bypass in the Brizy WordPress plugin. The plugin fails to verify that the user modifying a template owns the template, instead comparing a request parameter unrelated to the write operation. Users with Contributor-level or higher privileges can therefore alter the template-type metadata of templates belonging to other users. This allows unauthorized manipulation of site layouts and could facilitate further privilege escalation.
Affected Systems
All WordPress installations running Brizy Page Builder before version 2.8.19 are affected. The flaw applies to sites that have users assigned the Contributor role or higher, regardless of the WordPress core version. No other plugins or components are mentioned. The impact is confined to the Brizy plugin’s template management interface.
Risk and Exploitability
No CVSS or EPSS score is available, but the vulnerability enables authenticated users with Contributor or greater access to modify other users’ templates. Because the flaw is straightforward to exploit once a contributor account exists, the risk is considered high for sites that expose this role widely. No public exploit or KEV listing is documented, yet the broad attack surface and simple exploitation path warrant immediate attention. The potential for cascading effects justifies a high priority for remediation. Ends.
OpenCVE Enrichment