Cross-Site Scripting Vulnerability in Brizy WordPress Plugin
CVE-2026-16069
Key Information:
Badges
What is CVE-2026-16069?
The Brizy WordPress plugin prior to version 2.8.19 is susceptible to a Cross-Site Scripting (XSS) vulnerability due to inadequate sanitization and escaping of focal-point coordinates for featured images. This weakness allows users with Contributor privileges or higher to inject malicious scripts into the post editor's HTML attributes. When a higher-privileged user reviews the post, the injected script executes in their session, potentially compromising sensitive information and user interactions. Proper validation and escaping are essential to mitigate such security risks.
Affected Version(s)
Brizy 0 < 2.8.19
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.