CVE-2025-0969: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-0969 is a Sensitive Information Exposure vulnerability in the Brizy – Page Builder plugin for WordPress, affecting all versions up to and including 2.7.16. The flaw allows authenticated attackers with Contributor-level access or higher to extract sensitive data — including administrator email addresses and hashed passwords — via the get_users() function. It was published on December 13, 2025, and assigned a CVSS v3.1 base score of 6.5 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is classified as CWE-359 (Exposure of Private Personal Information to an Unauthorized Actor). The vulnerable get_users() function in the plugin's editor/api.php (around line 961) exposes WordPress user data — including administrator email addresses and hashed passwords — without adequately restricting the response to the requesting user's privilege level. An authenticated attacker with at minimum Contributor-level access can invoke this function over the network with no user interaction required, making exploitation straightforward (Wordfence, WordPress Trac).

Impact

Successful exploitation results in a high confidentiality impact: attackers can harvest administrator email addresses and hashed passwords from the WordPress database. While integrity and availability are not directly affected, the exposure of password hashes enables offline cracking attacks that could lead to full administrative account takeover, site defacement, malware injection, or further lateral movement within hosted environments. The scope is limited to the affected WordPress installation, but the data exposed is highly sensitive (Wordfence, ENISA EUVD).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.03%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low barrier to exploitation — requiring only a Contributor-level WordPress account — makes it a realistic risk on sites with open user registration (Wordfence, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Brizy – Page Builder plugin version ≤ 2.7.16 using tools like WPScan or by checking the plugin's readme.txt file at /wp-content/plugins/brizy/readme.txt.
  2. Obtain Contributor-level access: Register or log in as a Contributor-level (or higher) WordPress user on the target site.
  3. Invoke the vulnerable endpoint: Send an authenticated HTTP request to the Brizy plugin's API endpoint that triggers the get_users() function in editor/api.php (e.g., via a crafted AJAX or REST API call with a valid nonce).
  4. Extract sensitive data: Parse the API response, which improperly returns WordPress user data including administrator email addresses and hashed passwords.
  5. Offline password cracking: Use tools such as Hashcat or John the Ripper to attempt offline cracking of the exposed password hashes, potentially gaining full administrator access (Wordfence, WordPress Trac).

Indicators of compromise

  • Network: Unusual authenticated HTTP requests to Brizy plugin API endpoints (e.g., WordPress AJAX or REST routes associated with get_users) from Contributor-level accounts, especially in rapid succession or outside normal usage patterns.
  • Logs: WordPress access logs showing repeated POST requests to wp-admin/admin-ajax.php or similar endpoints with Brizy-specific action parameters from low-privilege user accounts; responses with unexpectedly large payloads containing user data.
  • File System: No direct file system artifacts expected from information disclosure alone; however, subsequent compromise may result in new admin accounts, modified theme/plugin files, or web shells.
  • Process/Behavior: New administrator accounts created shortly after Contributor-level login activity; unexpected changes to site content or settings following the exposure event (Wordfence).

Mitigation and workarounds

Update the Brizy – Page Builder plugin to version 2.7.17 or later, which addresses this vulnerability via the changeset available in the WordPress plugin repository (WordPress Trac Changeset). As an interim workaround, site administrators should restrict user registration and minimize the number of accounts with Contributor-level access or above. Monitoring authentication logs for unusual API activity from low-privilege accounts is also recommended (Wordfence, Sucuri Blog).

Community reactions

Wordfence disclosed and reported the vulnerability, including it in their weekly WordPress vulnerability report for December 8–14, 2025 (Wordfence Blog). Sucuri also highlighted it in their December 2025 vulnerability patch roundup (Sucuri Blog). Community reaction has been moderate, with standard coverage across vulnerability aggregators; no significant controversy or high-profile researcher commentary has been noted.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management