What is CVE-2026-16070?
This vulnerability (CVE-2026-16070) affects Brizy WordPress plugin versions before 2.8.19, where improper authorization checks allow users with Contributor-level access and above to modify a template's type meta. This is due to a mismatch between the parameter validated and the one used in the actual write operation. Immediate update to the latest version is strongly advised.
Azərbaycanca: Brizy WordPress plaqinində aşkar edilmiş bu boşluq (CVE-2026-16070) 2.8.19 versiyasından əvvəlki versiyalara təsir edir. O, Contributor və yuxarı səviyyəli istifadəçilərə şablonun tip meta məlumatını dəyişməyə imkan verən avtorizasiya zəifliyidir. Plaqini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which versions of the Brizy WordPress plugin are affected by CVE-2026-16070?
This vulnerability affects Brizy WordPress plugin versions before 2.8.19.
What level of user role is required to exploit CVE-2026-16070?
Exploiting this vulnerability requires Contributor-level access and above.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.