Impact
The Brizy – Page Builder plugin for WordPress contains a stored cross‑site scripting flaw. The vulnerable code is the rootAttributes parameter, which is not properly sanitized or escaped. When an authenticated user with Contributor or higher privileges injects malicious script content into this parameter, the script is persisted in the plugin’s storage and executed whenever a user visits the affected page. This allows the attacker to run arbitrary JavaScript in the context of any site visitor, enabling steganographic data exfiltration, session hijacking, or page defacement.
Affected Systems
All WordPress installations that have the Brizy – Page Builder plugin version 2.8.14 or earlier. The vulnerability is present in every site where a user with Contributor level or above is allowed to edit pages through this plugin. Any user who can view these pages will be exposed to the injected script.
Risk and Exploitability
The flaw scores a CVSS of 6.4, indicating a moderate severity. The EPSS score is below 1%, suggesting that exploitation is currently infrequent. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires that the attacker first gain access to a Contributor‑level account or have the ability to create content that is stored via the rootAttributes parameter. Once stored, the script runs for any user who visits the edited page.
OpenCVE Enrichment