Executive brief
Brizy is a popular WordPress page builder plugin used to design and manage website layouts. The plugin fails to properly validate permissions and sanitize user input when storing site-wide design code, allowing authors and higher-level users to inject malicious JavaScript that executes for all site visitors, including administrators. This could be exploited to steal admin credentials, deface the website, or inject malware.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw in the brizy_set_project AJAX action. The plugin does not properly restrict who can modify the site-global project data (accessible to Author-level users via the publish_posts capability) and fails to sanitize arbitrary JavaScript stored in the compiled styles field before outputting it on the front-end. An authenticated Author can obtain a valid nonce via the heartbeat endpoint, call brizy_set_project without the 'post' parameter to target the global project, and inject raw script tags into the compiled styles that are served unescaped in the HTML head to all visitors. The vulnerability affects versions before 2.8.19 and was fixed in that version.
Affected products
- Brizy Brizy before 2.8.19
Timeline
- 2026-07-27: disclosed
- 2026-08-04: patched: Fixed in version 2.8.19
- 2026-08-04: advisory