Executive brief
Brizy is a popular WordPress page builder plugin used to create and manage website templates. The plugin before version 2.8.19 contains an authorization flaw that allows contributor-level users to change the template type (e.g., from single-page to archive) of templates owned by other users, including administrators. This could allow a malicious contributor to disrupt template configurations or gain unauthorized control over site content structure.
Technical details
The vulnerability is an Insecure Direct Object Reference (IDOR) in the brizy_set_template_type AJAX handler. The plugin validates the nonce against the "post" request parameter but performs the write operation using the "template_id" parameter, allowing an attacker to omit the "post" parameter and modify templates they do not own. An authenticated Contributor-level user can call the vulnerable AJAX endpoint with a valid nonce, specifying any target template ID and desired template type (single, archive, single_product, or product_archive), bypassing per-object authorization checks. The vulnerability requires WordPress authentication (Contributor role or above, automatically granted by Brizy on activation) but no additional user interaction. Patches are available in version 2.8.19 and later.
Affected products
- Brizy Page Builder before 2.8.19
Timeline
- 2026-07-27: disclosed
- 2026-08-04: patched: Fixed in version 2.8.19