CVE-2026-16070
The Brizy WordPress plugin before 2.8.19 does not properly verify authorization on the object being modified before updating a template's t
CVSS
2.7
Bajo
EPSS
0.2%
p6
KEV
—
Exploit Today
2
0-100
Publicado: 4 ago 2026 · Última mod.: 26 ago 2026 · CWE-639
0.1%EPSS · 30 días0.2%
2026-08-042026-08-30
The Brizy WordPress plugin before 2.8.19 does not properly verify authorization on the object being modified before updating a template's type meta, validating a request parameter that is different from the one used in the write operation, allowing users with Contributor-level access and above to change the template-type assignment of templates owned by other users.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-812002.7 BAJ7.5%
——2The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with the instructor role to read other users' order billing details, including name, email address, phone number and postal address, by enumerating order IDs.22hCVE-2026-803114.3 MED4.7%
——1The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5 does not verify that a subscription belongs to the customer bound to the requesting customer-portal session before cancelling it, allowing a user with a confirmed portal session to cancel subscriptions belonging to other customers.
Exploitation requires the attacker to know the target subscription's identifier, which is high-entropy and not enumerable through the Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5.22hCVE-2026-192946.4 MED10.4%
——3IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute and read any user's private flow due to improper authorization.2dCVE-2026-189048.2 ALT23.2%
——7IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject unauthorized messages due to a namespace collision between user identifiers.2dCVE-2026-822905.3 MED10.9%
——3Chainlit through 2.12.0 fails to validate ownership of feedback records in PUT and DELETE endpoints. Authenticated attackers can delete or modify other users' feedback by supplying arbitrary feedback identifiers, corrupting human-rating data used for model evaluation.2dCVE-2026-822848.1 ALT14.7%
——4Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, DELETE /chat/{chat_id}, and POST /chat/{chat_id}/question/answer endpoints. Authenticated attackers can read other users' conversation histories including private knowledge base content, delete arbitrary chats, and inject fabricated messages into other users' conversations.2d