Unrated severityNVD Advisory· Published Jul 29, 2025· Updated Apr 8, 2026
Brizy <= 2.6.20 - Missing Authorization to Unauthenticated Limited File Upload
CVE-2025-4370
Description
The Brizy – Page Builder plugin for WordPress is vulnerable to limited file uploads due to missing authorization on process_external_asset_urls function as well as missing path validation in store_file function in all versions up to, and including, 2.6.20. This makes it possible for unauthenticated attackers to upload .TXT files on the affected site's server.
Affected products
2- Range: <=2.6.20
- themefusecom/Brizy – Page Builderv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.