VYPR

Brizy Page Builder

by Brizy

CVEs (3)

  • CVE-2021-38346HigOct 14, 2021
    risk 0.57cvss 8.8epss 0.02

    The Brizy Page Builder plugin <= 2.3.11 for WordPress allowed authenticated users to upload executable files to a location of their choice using the brizy_create_block_screenshot AJAX action. The file would be named using the id parameter, which could be prepended with "../" to…

  • CVE-2021-38345HigOct 14, 2021
    risk 0.46cvss 7.1epss 0.01

    The Brizy Page Builder plugin <= 2.3.11 for WordPress used an incorrect authorization check that allowed any logged-in user accessing any endpoint in the wp-admin directory to modify the content of any existing post or page created with the Brizy editor. An identical issue was…

  • CVE-2021-38344MedOct 14, 2021
    risk 0.42cvss 6.4epss 0.01

    The Brizy Page Builder plugin <= 2.3.11 for WordPress was vulnerable to stored XSS by lower-privileged users such as a subscribers. It was possible to add malicious JavaScript to a page by modifying the request sent to update the page via the brizy_update_item AJAX action and…