Description
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘rootAttributes’ parameter in all versions up to, and including, 2.8.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-09-17
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored XSS
Action: Immediate Patch
AI Analysis

Impact

The Brizy – Page Builder plugin for WordPress contains a stored cross‑site scripting flaw. The vulnerable code is the rootAttributes parameter, which is not properly sanitized or escaped. When an authenticated user with Contributor or higher privileges injects malicious script content into this parameter, the script is persisted in the plugin’s storage and executed whenever a user visits the affected page. This allows the attacker to run arbitrary JavaScript in the context of any site visitor, enabling steganographic data exfiltration, session hijacking, or page defacement.

Affected Systems

All WordPress installations that have the Brizy – Page Builder plugin version 2.8.14 or earlier. The vulnerability is present in every site where a user with Contributor level or above is allowed to edit pages through this plugin. Any user who can view these pages will be exposed to the injected script.

Risk and Exploitability

The flaw scores a CVSS of 6.4, indicating a moderate severity. The EPSS score is below 1%, suggesting that exploitation is currently infrequent. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires that the attacker first gain access to a Contributor‑level account or have the ability to create content that is stored via the rootAttributes parameter. Once stored, the script runs for any user who visits the edited page.

Generated by OpenCVE AI on September 19, 2026 at 01:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Brizy – Page Builder plugin to version 2.8.15 or later.
  • Restrict or revoke Contributor and higher permissions from users who do not need to edit page layouts.
  • If an immediate update is not possible, remove or strip any custom rootAttributes data from existing pages and ensure role‑based access controls are enforced.

Generated by OpenCVE AI on September 19, 2026 at 01:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Themefusecom
Themefusecom brizy – Page Builder
Wordpress
Wordpress wordpress
Vendors & Products Themefusecom
Themefusecom brizy – Page Builder
Wordpress
Wordpress wordpress

Thu, 17 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘rootAttributes’ parameter in all versions up to, and including, 2.8.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Brizy – Page Builder <= 2.8.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'rootAttributes' Parameter
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Themefusecom Brizy – Page Builder
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:21:52.847Z

Reserved: 2026-02-16T13:43:45.692Z

Link: CVE-2026-2585

cve-icon Vulnrichment

Updated: 2026-09-19T14:15:10.404Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T00:16:57.450

Modified: 2026-09-19T15:16:59.523

Link: CVE-2026-2585

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T01:15:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')