HomeWordPress vulnerabilitiesBrizy
Brizy vulnerabilities
Brizy has 28 known vulnerabilities in this database. The most recent published record is dated 18 Sep 2026.
- Known vulnerabilities
- 28
- Active installs
- 60,000+
- Latest version
- 2.8.23
- Last updated
- 9 Sep 2026
- Most recent
- 18 Sep 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Cross-site scripting (XSS) CVE-2026-2585 | Medium 6.4 | Up to 2.8.14 | Fixed in a later version (latest 2.8.23) | 18 Sep 2026 |
| Cross-site scripting (XSS) CVE-2026-16068 | Low 3.5 | Before 2.8.19 | Fixed in 2.8.19 | 4 Aug 2026 |
| Cross-site scripting (XSS) CVE-2026-16069 | Medium 6.8 | Before 2.8.19 | Fixed in 2.8.19 | 4 Aug 2026 |
| Broken access control CVE-2026-16070 | Low 2.7 | Before 2.8.19 | Fixed in 2.8.19 | 4 Aug 2026 |
| Broken access control CVE-2026-14195 | Low 2.7 | Before 2.8.18 | Fixed in 2.8.18 | 1 Aug 2026 |
| Cross-site scripting (XSS) CVE-2026-5324 | High 7.2 | Up to 2.8.11 | Fixed in a later version (latest 2.8.23) | 2 May 2026 |
| Sensitive data exposure CVE-2025-0969 | Medium 6.5 | Up to 2.7.16 | Fixed in a later version (latest 2.8.23) | 13 Dec 2025 |
| Broken access control CVE-2025-4370 | Medium 5.3 | Before 2.6.21 | Fixed in 2.6.21 | 29 Jul 2025 |
| Cross-site scripting (XSS) CVE-2024-10322 | Medium 6.4 | Before 2.6.9 | Fixed in 2.6.9 | 12 Feb 2025 |
| Remote code execution CVE-2024-10960 | Critical 9.9 | Before 2.6.5 | Fixed in 2.6.5 | 12 Feb 2025 |
| Cross-site scripting (XSS) CVE-2024-6254 | Medium 4.3 | Before 2.5.2 | Fixed in 2.5.2 | 8 Aug 2024 |
| Remote code execution CVE-2024-3242 | High 8.8 | Before 2.4.45 | Fixed in 2.4.45 | 18 Jul 2024 |
| Broken access control CVE-2024-1937 | High 7.1 | Before 2.4.45 | Fixed in 2.4.45 | 16 Jul 2024 |
| Cross-site scripting (XSS) CVE-2024-1164 | Medium 6.4 | Before 2.4.44 | Fixed in 2.4.44 | 5 Jun 2024 |
| Cross-site scripting (XSS) CVE-2024-3667 | High 7.4 | Before 2.4.44 | Fixed in 2.4.44 | 5 Jun 2024 |
| Cross-site scripting (XSS) CVE-2024-2087 | High 7.2 | Before 2.4.44 | Fixed in 2.4.44 | 5 Jun 2024 |
| Cross-site scripting (XSS) CVE-2024-1161 | Medium 6.4 | Before 2.4.44 | Fixed in 2.4.44 | 5 Jun 2024 |
| Cross-site scripting (XSS) CVE-2024-1940 | High 7.1 | Before 2.4.42 | Fixed in 2.4.42 | 5 Jun 2024 |
| Broken access control CVE-2024-3711 | Medium 4.3 | Before 2.4.44 | Fixed in 2.4.44 | 23 May 2024 |
| Cross-site scripting (XSS) CVE-2024-1293 | Medium 6.4 | Before 2.4.41 | Fixed in 2.4.41 | 13 Mar 2024 |
| Cross-site scripting (XSS) CVE-2024-1296 | Medium 6.4 | Before 2.4.41 | Fixed in 2.4.41 | 13 Mar 2024 |
| Remote code execution CVE-2024-1311 | High 8.8 | Before 2.4.41 | Fixed in 2.4.41 | 13 Mar 2024 |
| Cross-site scripting (XSS) CVE-2024-1291 | Medium 6.4 | Before 2.4.41 | Fixed in 2.4.41 | 13 Mar 2024 |
| Path traversal CVE-2024-1165 | Medium 4.3 | Before 2.4.40 | Fixed in 2.4.40 | 26 Feb 2024 |
| Broken access control CVE-2020-36714 | High 7.4 | Up to 1.0.125 | Fixed in a later version (latest 2.8.23) | 20 Oct 2023 |
| Security weakness CVE-2023-2897 | Low 3.7 | Up to 2.4.18 | Fixed in a later version (latest 2.8.23) | 9 Jun 2023 |
| Cross-site scripting (XSS) CVE-2022-2040 | Medium 5.4 | Before 2.4.2 | Fixed in 2.4.2 | 27 Jun 2022 |
| Cross-site scripting (XSS) CVE-2022-2041 | Medium 5.4 | Before 2.4.2 | Fixed in 2.4.2 | 27 Jun 2022 |
Read the published descriptions
- CVE-2026-2585, 18 Sep 2026
- The Brizy - Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘rootAttributes’ parameter in all versions up to, and including, 2.8.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2026-16068, 4 Aug 2026
- The Brizy WordPress plugin before 2.8.19 does not properly restrict who can modify its site-global design data and does not sanitise part of that data before outputting it, allowing authenticated users with Author-level access and above to store arbitrary JavaScript that is then served unsanitised on the site's front-end pages and executes in the browser of every visitor, including administrators. CVE record
- CVE-2026-16069, 4 Aug 2026
- The Brizy WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coordinates submitted through one of its AJAX actions before storing them and later echoing them into HTML attributes in the post editor's Featured Image meta box, allowing users with the Contributor role or above to inject arbitrary web scripts that execute in the session of a higher-privileged user who opens the post for review. CVE record
- CVE-2026-16070, 4 Aug 2026
- The Brizy WordPress plugin before 2.8.19 does not properly verify authorization on the object being modified before updating a template's type meta, validating a request parameter that is different from the one used in the write operation, allowing users with Contributor-level access and above to change the template-type assignment of templates owned by other users. CVE record
- CVE-2026-14195, 1 Aug 2026
- The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning post content, allowing users with the Contributor role or higher to read the content of arbitrary posts, including other users' private, pending, and draft posts. CVE record
- CVE-2026-5324, 2 May 2026
- The Brizy - Page Builder plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in all versions up to, and including, 2.8.11 This is due to a combination of missing nonce verification for unauthenticated form submissions, insufficient handling of FileUpload fields when no file is uploaded, and the reversal of security encoding via html_entity_decode() followed by unescaped output in the admin view. The submit_form() function skips nonce verification for non-logged-in users (api.php:198). The handleFileTypeFields() function fails to overwrite user-supplied values when no file is attached. While htmlentities() is applied during storage, html_entity_decode() reverses this on display (form-entries.php:79). The form-data.php template outputs FileUpload values directly in href attributes without esc_url(). This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the form Leads page. CVE record
- CVE-2025-0969, 13 Dec 2025
- The Brizy - Page Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.16 via the get_users() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including email addresses and hashed passwords of administrators. CVE record
- CVE-2025-4370, 29 Jul 2025
- The Brizy - Page Builder plugin for WordPress is vulnerable to limited file uploads due to missing authorization on process_external_asset_urls function as well as missing path validation in store_file function in all versions up to, and including, 2.6.20. This makes it possible for unauthenticated attackers to upload .TXT files on the affected site's server. CVE record
- CVE-2024-10322, 12 Feb 2025
- The Brizy - Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 2.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file. CVE record
- CVE-2024-10960, 12 Feb 2025
- The Brizy - Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'storeUploads' function in all versions up to, and including, 2.6.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. CVE record
- CVE-2024-6254, 8 Aug 2024
- The Brizy - Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.1. This is due to missing or incorrect nonce validation on form submissions. This makes it possible for unauthenticated attackers to submit forms intended for public use as another user via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. On sites where unfiltered_html is enabled, this can lead to the admin unknowingly adding a Stored Cross-Site Scripting payload. CVE record
- CVE-2024-3242, 18 Jul 2024
- The Brizy - Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension validation in the validateImageContent function called via storeImages in all versions up to, and including, 2.4.43. This makes it possible for authenticated attackers, with contributor access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. Version 2.4.44 prevents the upload of files ending in .sh and .php. Version 2.4.45 fully patches the issue. CVE record
- CVE-2024-1937, 16 Jul 2024
- The Brizy - Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_item' function in all versions up to, and including, 2.4.44. This makes it possible for authenticated attackers, with contributor access and above, to modify the content of arbitrary published posts, which includes the ability to insert malicious JavaScript. CVE record
- CVE-2024-1164, 5 Jun 2024
- The Brizy - Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's contact form widget error message and redirect URL in all versions up to, and including, 2.4.43 due to insufficient input sanitization and output escaping on user supplied error messages. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-3667, 5 Jun 2024
- The Brizy - Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Link To' field of multiple widgets in all versions up to, and including, 2.4.43 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-2087, 5 Jun 2024
- The Brizy - Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form name values in all versions up to, and including, 2.4.43 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-1161, 5 Jun 2024
- The Brizy - Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Custom Attributes for blocks in all versions up to, and including, 2.4.43 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-1940, 5 Jun 2024
- The Brizy - Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post content in all versions up to, and including, 2.4.41 due to insufficient input sanitization performed only on the client side and insufficient output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-3711, 23 May 2024
- The Brizy - Page Builder plugin for WordPress is vulnerable to unauthorized plugin setting update due to a missing capability check on the functions action_request_disable, action_change_template, and action_request_enable in all versions up to, and including, 2.4.43. This makes it possible for authenticated attackers, with contributor access or above, to enable/disable the Brizy editor and modify the template used. CVE record
- CVE-2024-1293, 13 Mar 2024
- The Brizy - Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the embedded media custom block in all versions up to, and including, 2.4.40 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-1296, 13 Mar 2024
- The Brizy - Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block upload in all versions up to, and including, 2.4.40 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-1311, 13 Mar 2024
- The Brizy - Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the storeImages function in all versions up to, and including, 2.4.40. This makes it possible for authenticated attackers, with contributor access or above, to upload arbitrary files on the affected site's server which may make remote code execution possible. CVE record
- CVE-2024-1291, 13 Mar 2024
- The Brizy - Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown URL parameter in all versions up to, and including, 2.4.40 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-1165, 26 Feb 2024
- The Brizy - Page Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.39 via the 'id'. This makes it possible for authenticated attackers, with contributor-level access and above, to upload files to arbitrary locations on the server CVE record
- CVE-2020-36714, 20 Oct 2023
- The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_administrator() function in versions up to, and including, 1.0.125. This makes it possible for authenticated attackers to access and interact with available AJAX functions. CVE record
- CVE-2023-2897, 9 Jun 2023
- The Brizy Page Builder plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.4.18. This is due to an implicit trust of user-supplied IP addresses in an 'X-Forwarded-For' HTTP header for the purpose of validating allowed IP addresses against a Maintenance Mode whitelist. Supplying a whitelisted IP address within the 'X-Forwarded-For' header allows maintenance mode to be bypassed and may result in the disclosure of potentially sensitive information or allow access to restricted functionality. CVE record
- CVE-2022-2040, 27 Jun 2022
- The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element URL, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks CVE record
- CVE-2022-2041, 27 Jun 2022
- The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element content, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks CVE record
What to do if you run Brizy
If you run Brizy, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Brizy vulnerabilities
Free. We email you when a new vulnerability is published for Brizy, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.