What is CVE-2026-14195?
The Brizy WordPress plugin before version 2.8.18 fails to properly verify authorization on a request handler, allowing users with the Contributor role or higher to read arbitrary post content, including private, pending, and draft posts. Updating the plugin to the latest version is recommended.
Azərbaycanca: Brizy WordPress plaqini 2.8.18-dən əvvəlki versiyalarda sorğu idarəedicisində avtorizasiyanı düzgün yoxlamır. Bu, Contributor və daha yüksək rol sahiblərinə digər istifadəçilərin şəxsi, gözləmədə olan və qaralama yazılarının məzmununu oxumağa imkan verir. Plaqini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the Brizy plugin are affected by CVE-2026-14195, and which user role can exploit it?
The vulnerability affects Brizy WordPress plugin versions before 2.8.18. Users with the Contributor role or higher can exploit it to read the content of other users' private, pending, and draft posts.
What is the recommended action to mitigate CVE-2026-14195?
Updating the Brizy plugin to the latest version is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.