CVE-2026-16069: CWE-79 Cross-Site Scripting (XSS) in Brizy
The Brizy WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coordinates submitted through one of its AJAX actions before storing them and later echoing them into HTML attributes in the post editor's Featured Image meta box, allowing users with the Contributor role or above to inject arbitrary web scripts that execute in the session of a higher-privileged user who opens the post for review.
AI Analysis
Technical Summary
The Brizy WordPress plugin versions prior to 2.8.19 do not properly sanitize or escape user-supplied featured-image focal-point coordinates submitted through an AJAX action. These coordinates are stored and later output into HTML attributes within the post editor's Featured Image meta box without adequate escaping. This enables users with Contributor role or above to inject malicious scripts that execute when a higher-privileged user opens the post for review, constituting a stored Cross-Site Scripting (CWE-79) vulnerability.
Potential Impact
Successful exploitation allows users with Contributor or higher roles to execute arbitrary JavaScript in the browser context of higher-privileged users (e.g., Editors or Administrators) when they view the affected post. This could lead to session hijacking, privilege escalation, or other malicious actions within the WordPress admin interface.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict Contributor role users from accessing the affected AJAX functionality or disable the Brizy plugin if feasible. Monitor vendor channels for updates and apply the patch once released.
CVE-2026-16069: CWE-79 Cross-Site Scripting (XSS) in Brizy
Description
The Brizy WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coordinates submitted through one of its AJAX actions before storing them and later echoing them into HTML attributes in the post editor's Featured Image meta box, allowing users with the Contributor role or above to inject arbitrary web scripts that execute in the session of a higher-privileged user who opens the post for review.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Brizy WordPress plugin versions prior to 2.8.19 do not properly sanitize or escape user-supplied featured-image focal-point coordinates submitted through an AJAX action. These coordinates are stored and later output into HTML attributes within the post editor's Featured Image meta box without adequate escaping. This enables users with Contributor role or above to inject malicious scripts that execute when a higher-privileged user opens the post for review, constituting a stored Cross-Site Scripting (CWE-79) vulnerability.
Potential Impact
Successful exploitation allows users with Contributor or higher roles to execute arbitrary JavaScript in the browser context of higher-privileged users (e.g., Editors or Administrators) when they view the affected post. This could lead to session hijacking, privilege escalation, or other malicious actions within the WordPress admin interface.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict Contributor role users from accessing the affected AJAX functionality or disable the Brizy plugin if feasible. Monitor vendor channels for updates and apply the patch once released.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-07-17T13:18:03.270Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7187d0bf32cb7a34e19ad9
Added to database: 08/04/2026, 06:33:52 UTC
Last enriched: 08/04/2026, 06:54:03 UTC
Last updated: 08/04/2026, 12:56:01 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.