CyberRota Analysis
AI-GeneratedThe Brizy WordPress plugin prior to version 2.8.19 is vulnerable due to inadequate restrictions on modifying site-global design data and a lack of sanitization, allowing authenticated users with Author-level access or higher to inject arbitrary JavaScript. This flaw can lead to cross-site scripting (XSS) attacks, impacting all site visitors, including administrators, by executing malicious scripts in their browsers. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate the risk.
Original NVD Description
The Brizy WordPress plugin before 2.8.19 does not properly restrict who can modify its site-global design data and does not sanitise part of that data before outputting it, allowing authenticated users with Author-level access and above to store arbitrary JavaScript that is then served unsanitised on the site's front-end pages and executes in the browser of every visitor, including administrators.