Impact
The Brizy WordPress plugin version 2.8.18 and earlier does not restrict which users can modify its site‑global design data and does not properly sanitize part of that data before outputting it. Authenticated users with Author or higher privileges can therefore store arbitrary JavaScript in the global project code asset; this code is rendered unsanitized on all front‑end pages and executes in the browsers of every site visitor, including administrators. This stored XSS flaw gives an attacker a broad and high‑impact avenue to steal credentials, hijack sessions, deface content or otherwise compromise the site’s integrity, confidentiality, or availability. The weakness corresponds to CWE‑79.
Affected Systems
WordPress sites that active the Brizy plugin, any deployment running a version prior to 2.8.19. There are no additional vendor or product filters specified, so any installation of the vulnerable plugin is impacted.
Risk and Exploitability
The CVSS score is 3.5, but the flaw allows exploitation by any authenticated author‑level account, which are common on many WordPress sites. The EPSS score is < 1%, indicating a low probability of exploitation, but the lack of a KEV listing does not diminish the risk given the high potential impact. Because the attacker can inject script that runs in the context of all site visitors, the threat exposure remains significant for systems with broad author access. The required conditions are relatively low: simply obtain Author or higher credentials and use the plugin’s interface to store malicious code.
OpenCVE Enrichment