Impact
The vulnerability is a missing authorization flaw in the themefusecom Brizy WordPress plugin that allows exploitation of incorrectly configured access control security levels. Because the plugin does not properly check user permissions, an attacker could potentially gain unauthorized access to restricted plugin features or data, leading to potential exposure of confidential information or further exploitation of the WordPress site. The weakness is identified as CWE-862, indicating inadequate authorization.
Affected Systems
All installs of the Brizy plugin from the earliest released version up through version 2.7.23 are affected. This includes any WordPress site that has the plugin in use at a version equal to or lower than 2.7.23.
Risk and Exploitability
The CVSS score of 4.3 classifies the vulnerability as low, and the EPSS score of less than 1% indicates a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, further suggesting limited exploitation risk. Based on the description, it is inferred that the attack may require a user account with some administrative or plugin‑management privileges, but misconfiguration could allow non‑privileged users to bypass intended controls. The risk is thereby limited to unauthorized access for users who can exploit the misconfigured access control settings.
OpenCVE Enrichment