Access violation vulnerability in Bricks Builder 1.9.8

The Bricks Builder plugin for WordPress has a security vulnerability in all versions up to 1.9.8. This vulnerability is called Insecure Direct Object Reference and it is caused by not checking a key that is controlled by the user. This means that people who are logged in and have Contributor-level access or higher can change posts and pages that were created by other users, even admins. To do this, an admin would have to give access to the editor for that specific user or for all users with a certain type of account.

Detected in:

Bricks Builder fixed vulnerable versions: >= * <= 1.9.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.