Insecure WordPress plugin exposes thousands of sites to takeover attacks

data privacy
(Image credit: Shutterstock / Zeeker2526)

Researchers have disclosed a series of vulnerabilities that could have exposed thousands of WordPress websites to takeover attacks.

According to a blog post from security firm Wordfence, the bugs were present in Brizy - Page Builder, a WordPress plugin installed across more than 90,000 sites. Although a fix has now been released, it’s likely a number of installations remain unpatched.

If exploited, one chain of vulnerabilities could reportedly allow attackers to execute “complete site takeover” and add malicious JavaScript to existing posts. Separately, another of the vulnerabilities could be exploited to upload executable files and achieve remote code execution.

As per the Common Vulnerability Scoring System (CVSS), the Brizy - Page Builder bugs range in severity from medium (6.4) to high (8.8).

WordPress plugin vulnerability

he researchers were first alerted to a potential problem when they observed unusual traffic relating to the Brizy - Page Builder plugin. Although the plugin was not under active attack, the group was able to identify a selection of interconnected bugs.

“[The unusual traffic] led us to discover two new vulnerabilities as well as a previously patched access control vulnerability in the plugin that had been reintroduced,” Wordfence explained. “Both new vulnerabilities could take advantage of the access control vulnerability to allow complete site takeover.”

The nature of these vulnerabilities was such that any registered user (including subscribers) could pass for an administrator and modify posts and pages, even if they had already been published to the site.

The issues were identified by Wordfence in early June. After a full investigation was conducted, the researchers notified the vendor of the vulnerabilities in mid-August and a full patch was released roughly a week later.

To shield against attack, WordPress users are advised to update to the latest version of the Brizy - Page Builder plugin (version 2.3.17) immediately.

TOPICS
Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Read more
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Another serious WordPress plugin vulnerability could put 40,000 sites at risk of attack
WordPress
Another top WordPress plugin found carrying critical security flaws
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Thousands of WordPress websites hit in new malware attack, here's what we know
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Over a million WordPress sites exposed to attack from W3 Total Cache plugin flaw
WordPress
WordPress users beware - these popular theme plugins have some major security issues
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand