Impact
The Brizy WordPress plugin fails to sanitize or escape featured‑image focal‑point coordinates submitted through an AJAX action before they are stored. These coordinates are later echoed into HTML attributes in the Featured Image meta box of the post editor. As a result, a user with the Contributor role or higher can inject arbitrary JavaScript that will execute in the browser context of any user who opens the edited post for review.
Affected Systems
WordPress sites running the Brizy plugin with versions earlier than 2.8.19 are vulnerable. The flaw applies to any installation where a Contributor or higher can submit featured‑image focal points, regardless of the site's user base or specific configuration.
Risk and Exploitability
The vulnerability has an EPSS score of less than 1% and is not listed in CISA’s KEV catalog. It allows an attacker with Contributor access to inject JavaScript that executes in the browser context of any higher‑privileged user who opens the edited post for review. This gives the attacker the ability to execute arbitrary code, potentially compromising confidentiality or integrity of the page contents during the review process. The CVSS score of 6.8 indicates a moderate severity.
OpenCVE Enrichment