Missing Authorization Vulnerability in Brizy by ThemeFuse
CVE-2026-32408

4.3MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
13 March 2026

What is CVE-2026-32408?

A missing authorization vulnerability exists in Brizy by ThemeFuse that allows attackers to exploit improperly configured access control security levels. This issue could potentially allow unauthorized users to gain access to sensitive functionalities, putting user data at risk. Affected versions include all prior to and including 2.7.23. It is crucial for users of Brizy to evaluate their configurations and update to avoid exposure to these security risks.

Affected Version(s)

Brizy 0 <= 2.7.23

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jakub Herman | Patchstack Bug Bounty Program
.