Brizy
cpe:2.3:a:brizy:brizy:*:*:*:*:wordpress:*:*
- <= 2.8.11
A stored cross-site scripting vulnerability has been identified in the Brizy Page Builder plugin for WordPress, affecting all versions through 2.8.11. This vulnerability allows unauthenticated users to inject malicious scripts that are executed when an administrator views the form Leads page. The issue arises from a lack of nonce verification for unauthenticated form submissions, inadequate handling of FileUpload fields when no file is uploaded, and the reversal of security encoding followed by unescaped output in the admin view.
Exploitation of this vulnerability allows for unauthenticated stored cross-site scripting, where injected scripts are executed in the context of an administrator.
Users can update to Brizy Page Builder version 2.8.12 or a newer patched version to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.