AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-16068

UNKNOWN · CVSS N/A EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-04

CyberRota Analysis

AI-Generated

The Brizy WordPress plugin prior to version 2.8.19 is vulnerable due to inadequate restrictions on modifying site-global design data and a lack of sanitization, allowing authenticated users with Author-level access or higher to inject arbitrary JavaScript. This flaw can lead to cross-site scripting (XSS) attacks, impacting all site visitors, including administrators, by executing malicious scripts in their browsers. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate the risk.

CVE
CVE-2026-16068
Severity
UNKNOWN
CVSS
N/A
EPSS
0.16%
WordPress Java

Original NVD Description

The Brizy WordPress plugin before 2.8.19 does not properly restrict who can modify its site-global design data and does not sanitise part of that data before outputting it, allowing authenticated users with Author-level access and above to store arbitrary JavaScript that is then served unsanitised on the site's front-end pages and executes in the browser of every visitor, including administrators.