Unrated severityNVD Advisory· Published Oct 14, 2021· Updated Feb 14, 2025
Brizy <= 2.3.11 Authenticated Stored Cross-Site Scripting
CVE-2021-38344
Description
The Brizy Page Builder plugin <= 2.3.11 for WordPress was vulnerable to stored XSS by lower-privileged users such as a subscribers. It was possible to add malicious JavaScript to a page by modifying the request sent to update the page via the brizy_update_item AJAX action and adding JavaScript to the data parameter, which would be executed in the session of any visitor viewing or previewing the post or page.
Affected products
1- Range: 2.3.11
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.