Medium severity6.4NVD Advisory· Published Oct 14, 2021· Updated Jun 17, 2026
CVE-2021-38344
CVE-2021-38344
Description
The Brizy Page Builder plugin <= 2.3.11 for WordPress was vulnerable to stored XSS by lower-privileged users such as a subscribers. It was possible to add malicious JavaScript to a page by modifying the request sent to update the page via the brizy_update_item AJAX action and adding JavaScript to the data parameter, which would be executed in the session of any visitor viewing or previewing the post or page.
Affected products
2- Range: <=2.3.11
- Range: 2.3.11
Patches
Vulnerability mechanics
References
1- www.wordfence.com/blog/2021/10/multiple-vulnerabilities-in-brizy-page-builder-plugin-allow-site-takeover/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.