SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-38344

The Brizy Page Builder plugin <= 2.3.11 for WordPress was vulnerable to stored XSS by lower-privileged users such as a subscribers.

MEDIUM 5.4EPSS 0.63%

Does this matter?

Lower severity and a low EPSS score (0.63%). Track it; it rarely justifies an emergency change on its own.

Description

The Brizy Page Builder plugin <= 2.3.11 for WordPress was vulnerable to stored XSS by lower-privileged users such as a subscribers. It was possible to add malicious JavaScript to a page by modifying the request sent to update the page via the brizy_update_item AJAX action and adding JavaScript to the data parameter, which would be executed in the session of any visitor viewing or previewing the post or page.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
0.63% probability · 48th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
brizy/brizy-page builder
Source
security@wordfence.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.