What the vulnerability does
01Description
The Brizy Page Builder plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.4.18. This is due to an implicit trust of user-supplied IP addresses in an 'X-Forwarded-For' HTTP header for the purpose of validating allowed IP addresses against a Maintenance Mode whitelist. Supplying a whitelisted IP address within the 'X-Forwarded-For' header allows maintenance mode to be bypassed and may result in the disclosure of potentially sensitive information or allow access to restricted functionality.
Explanation of Vulnerability in Simple Terms
02Summary
Brizy Page Builder versions up to 2.4.18 contain a flaw that allows an attacker to read limited sensitive information through the network. The vulnerability requires specific conditions to exploit and has low confidentiality impact. No integrity or availability impact is present. Site administrators should update to a version newer than 2.4.18.
What an attacker can do
03Attacker Capabilities
Read limited sensitive information from the site over the network.
Potential impact on your site
04Site Impact
Sensitive data may be exposed to unauthenticated attackers, though impact is limited.
Conditions required to exploit
05Prerequisites
Network access; specific conditions must be met to trigger the vulnerability.
Key dates
06Disclosure timeline
June 9, 2023
CVE published
April 8, 2026
Record updated