Ghostwire

CVE-2026-14195: The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning...

MEDIUM CVSS 0.0

Published: August 1, 2026 | Last Modified: August 1, 2026

Description

The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning post content, allowing users with the Contributor role or higher to read the content of arbitrary posts, including other users' private, pending, and draft posts.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

References