Description
The Brizy – Page Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.16 via the get_users() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including email addresses and hashed passwords of administrators.
Problem types
CWE-359 Exposure of Private Personal Information to an Unauthorized Actor
Product status
* (semver)
Timeline
| 2025-12-12: | Disclosed |
Credits
Matthew Rollings
References
www.wordfence.com/...-15d6-4ecf-894c-f22c8726402b?source=cve
plugins.trac.wordpress.org/...ser/brizy/trunk/editor/api.php
plugins.trac.wordpress.org/changeset/3392844
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.