Insufficient Access Control in Brizy Plugin for WordPress
CVE-2026-16068

Currently unrated

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
4 August 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-16068?

The Brizy plugin for WordPress prior to version 2.8.19 exhibits poor access control, failing to restrict modifications to site-global design data effectively. This oversight allows authenticated users with Author-level permissions or higher to input arbitrary JavaScript code. The plugin does not adequately sanitize this data before it is outputted, leading to execution in the browsers of visitors to the site, which can affect all users, including site administrators.

Affected Version(s)

Brizy 0 < 2.8.19

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muni Nitish Kumar Yaddala
WPScan
.