CVE-2026-16068
Received Received - Intake

Stored Cross-Site Scripting in Brizy WordPress Plugin

Vulnerability report for CVE-2026-16068, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-04

Assigner: WPScan

Description

The Brizy WordPress plugin before 2.8.19 does not properly restrict who can modify its site-global design data and does not sanitise part of that data before outputting it, allowing authenticated users with Author-level access and above to store arbitrary JavaScript that is then served unsanitised on the site's front-end pages and executes in the browser of every visitor, including administrators.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-04
Generated
2026-08-04
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
brizy brizy to 2.8.19 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Brizy WordPress plugin before version 2.8.19 has a vulnerability where authenticated users with Author-level access or higher can inject arbitrary JavaScript into site-global design data. This JavaScript is then served unsanitized on front-end pages and executes in the browsers of all visitors, including administrators.

Detection Guidance

Check if the Brizy WordPress plugin version is below 2.8.19. Inspect site-global design data for unauthorized JavaScript modifications. Review browser console logs for unexpected scripts on front-end pages.

Impact Analysis

This vulnerability allows attackers to execute malicious JavaScript on your website, potentially stealing user data, session cookies, or performing actions on behalf of users. It affects all visitors, including administrators, compromising site integrity and security.

Compliance Impact

This vulnerability could lead to data breaches, violating GDPR and HIPAA requirements for data protection and security. It may result in unauthorized access to personal data, triggering legal penalties and compliance failures.

Mitigation Strategies

Update the Brizy plugin to version 2.8.19 or later. Remove any unauthorized JavaScript from site-global design data. Restrict Author-level access to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16068. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart