The Brizy WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coordinates submitted through one of its AJAX actions before storing them and later echoing them into HTML attributes in the post editor's Featured Image meta box, allowing users with the Contributor role or above to inject arbitrary web scripts that execute in the session of a higher-privileged user who opens the post for review.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Brizy
Brizy brizy Wordpress Wordpress wordpress |
|
| Vendors & Products |
Brizy
Brizy brizy Wordpress Wordpress wordpress |
Tue, 04 Aug 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Brizy WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coordinates submitted through one of its AJAX actions before storing them and later echoing them into HTML attributes in the post editor's Featured Image meta box, allowing users with the Contributor role or above to inject arbitrary web scripts that execute in the session of a higher-privileged user who opens the post for review. | |
| Title | Brizy - Page Builder < 2.8.19 - Contributor+ Stored XSS via Featured Image Focal Point | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-04T06:00:12.050Z
Reserved: 2026-07-17T13:18:03.270Z
Link: CVE-2026-16069
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-04T07:30:05Z