
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-0969 is a Sensitive Information Exposure vulnerability in the Brizy – Page Builder plugin for WordPress, affecting all versions up to and including 2.7.16. The flaw allows authenticated attackers with Contributor-level access or higher to extract sensitive data — including administrator email addresses and hashed passwords — via the get_users() function. It was published on December 13, 2025, and assigned a CVSS v3.1 base score of 6.5 (Medium) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-359 (Exposure of Private Personal Information to an Unauthorized Actor). The vulnerable get_users() function in the plugin's editor/api.php (around line 961) exposes WordPress user data — including administrator email addresses and hashed passwords — without adequately restricting the response to the requesting user's privilege level. An authenticated attacker with at minimum Contributor-level access can invoke this function over the network with no user interaction required, making exploitation straightforward (Wordfence, WordPress Trac).
Successful exploitation results in a high confidentiality impact: attackers can harvest administrator email addresses and hashed passwords from the WordPress database. While integrity and availability are not directly affected, the exposure of password hashes enables offline cracking attacks that could lead to full administrative account takeover, site defacement, malware injection, or further lateral movement within hosted environments. The scope is limited to the affected WordPress installation, but the data exposed is highly sensitive (Wordfence, ENISA EUVD).
No public exploit code or active in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.03%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low barrier to exploitation — requiring only a Contributor-level WordPress account — makes it a realistic risk on sites with open user registration (Wordfence, Red Hat CVE).
/wp-content/plugins/brizy/readme.txt.get_users() function in editor/api.php (e.g., via a crafted AJAX or REST API call with a valid nonce).get_users) from Contributor-level accounts, especially in rapid succession or outside normal usage patterns.wp-admin/admin-ajax.php or similar endpoints with Brizy-specific action parameters from low-privilege user accounts; responses with unexpectedly large payloads containing user data.Update the Brizy – Page Builder plugin to version 2.7.17 or later, which addresses this vulnerability via the changeset available in the WordPress plugin repository (WordPress Trac Changeset). As an interim workaround, site administrators should restrict user registration and minimize the number of accounts with Contributor-level access or above. Monitoring authentication logs for unusual API activity from low-privilege accounts is also recommended (Wordfence, Sucuri Blog).
Wordfence disclosed and reported the vulnerability, including it in their weekly WordPress vulnerability report for December 8–14, 2025 (Wordfence Blog). Sucuri also highlighted it in their December 2025 vulnerability patch roundup (Sucuri Blog). Community reaction has been moderate, with standard coverage across vulnerability aggregators; no significant controversy or high-profile researcher commentary has been noted.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."