Cross-Site Scripting Vulnerability in Brizy WordPress Plugin
CVE-2026-16069

Currently unrated

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
4 August 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-16069?

The Brizy WordPress plugin prior to version 2.8.19 is susceptible to a Cross-Site Scripting (XSS) vulnerability due to inadequate sanitization and escaping of focal-point coordinates for featured images. This weakness allows users with Contributor privileges or higher to inject malicious scripts into the post editor's HTML attributes. When a higher-privileged user reviews the post, the injected script executes in their session, potentially compromising sensitive information and user interactions. Proper validation and escaping are essential to mitigate such security risks.

Affected Version(s)

Brizy 0 < 2.8.19

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muni Nitish Kumar Yaddala
WPScan
.