Junglewise Threat Intelligence

CVE-2026-56009: Bricksable Bricksable for Bricks Builder Stored XSS

CVE-2026-56009 · Severity: medium · CVSS 5.9 · Published 2026-06-18

Executive brief

Bricksable is a WordPress plugin that provides additional elements and features for the Bricks Builder website design tool. A security vulnerability in this plugin allows an attacker with high-level permissions to inject malicious scripts into the website. If a site administrator or visitor views the affected page, these scripts could be used to redirect users to malicious sites, display unauthorized advertisements, or compromise user sessions.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Bricksable for Bricks Builder plugin for WordPress due to improper neutralization of input during web page generation (CWE-79). The flaw allows an attacker with high privileges (such as an Author or Editor) to inject malicious HTML or JavaScript payloads that are stored on the server. Successful exploitation requires a victim to interact with the affected page or element. This can lead to unauthorized script execution in the context of the victim's browser, potentially resulting in session hijacking or site defacement. The issue is fixed in version 1.6.84.

Affected products

  • Bricksable Bricksable for Bricks Builder n/a through 1.6.83

Timeline

  • 2026-06-10: other: Reported by researcher Ananda Dhakal
  • 2026-06-18: disclosed: Vulnerability published by Patchstack
  • 2026-06-18: patched: Version 1.6.84 released to address the issue

References