CVE-2026-16069
Received Received - Intake

Stored Cross-Site Scripting in Brizy WordPress Plugin

Vulnerability report for CVE-2026-16069, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-04

Assigner: WPScan

Description

The Brizy WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coordinates submitted through one of its AJAX actions before storing them and later echoing them into HTML attributes in the post editor's Featured Image meta box, allowing users with the Contributor role or above to inject arbitrary web scripts that execute in the session of a higher-privileged user who opens the post for review.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-04
Generated
2026-08-04
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
brizy brizy to 2.8.19 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a stored cross-site scripting (XSS) flaw in the Brizy WordPress plugin before version 2.8.19. It allows users with Contributor role or higher to inject malicious scripts by submitting unsanitized featured-image focal-point coordinates through an AJAX action. These scripts are later executed when a higher-privileged user views the post editor.

Detection Guidance

Check if the Brizy WordPress plugin version is below 2.8.19. Inspect AJAX actions for unsanitized featured-image focal-point submissions. Look for unusual scripts in the post editor's Featured Image meta box.

Impact Analysis

If exploited, this vulnerability could allow attackers to execute arbitrary web scripts in the browser of a privileged user, such as an administrator. This could lead to unauthorized actions, data theft, or session hijacking within the WordPress site.

Compliance Impact

This vulnerability could compromise data integrity and confidentiality, potentially violating GDPR or HIPAA requirements for protecting user data. Unauthorized script execution may lead to data breaches or unauthorized access, triggering compliance violations.

Mitigation Strategies

Update the Brizy plugin to version 2.8.19 or later. Remove any suspicious scripts from the Featured Image meta box. Restrict user roles to minimize exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16069. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart