{"id":"CVE-2026-16070","published":"2026-08-04T07:16:29.800","lastModified":"2026-08-04T15:16:26.320","description":"The Brizy  WordPress plugin before 2.8.19 does not properly verify authorization on the object being modified before updating a template's type meta, validating a request parameter that is different from the one used in the write operation, allowing users with Contributor-level access and above to change the template-type assignment of templates owned by other users.","cvssScore":2.7,"cvssSeverity":"LOW","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","cwes":["CWE-639"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/aa57d5b9-ba51-476c-9e64-fd431b89fa8a/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}