Junglewise Threat Intelligence

CVE-2025-69103: Utillz Brikk arbitrary content deletion

CVE-2025-69103 · Severity: high · CVSS 7.5 · Published 2026-06-17

Executive brief

The Brikk theme for WordPress, used for building directory and listing websites, contains a security flaw that allows users with low-level 'Subscriber' accounts to delete website content. An attacker could use this to remove critical site data such as posts, pages, or images, leading to significant data loss and service disruption. There is currently no official patch available from the developer.

Technical details

A missing authorization vulnerability (CWE-862) in the Brikk WordPress theme allows authenticated users with Subscriber-level privileges to delete arbitrary content. The flaw exists in the theme's handling of content management requests, where it fails to properly verify if the requesting user has the permission to delete the specified resource. An attacker can exploit this over the network to delete posts, pages, or media attachments. As of the advisory date, no official patch has been released by the vendor (Utillz), and users are advised to seek third-party mitigation or alternative themes.

Affected products

  • Utillz Brikk <= 3.0.0

Timeline

  • 2025-10-13: other: Vulnerability reported by researcher Denver Jackson
  • 2026-05-26: advisory: Patchstack published initial advisory
  • 2026-06-17: disclosed: CVE published to NVD

References