CVE-2022-2040: Brizy Page Builder < 2.4.2 - Contributor+ Stored Cross-Site Scripting via Element URL
Published Jun 27, 2022
·Updated
The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element URL, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks
Affected Software
2 affected components
Brizy Brizy WordPress<2.4.2
Brizy Brizy-page Builder Wordpress<2.4.2
Event History
Jun 27, 2022
CVE Published
via MITRE·08:59 AM
Data Sourced
via MITRE·08:59 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Brizy WordPress plugin vulnerability?
The vulnerability ID for this Brizy WordPress plugin vulnerability is CVE-2022-2040.
2
What is the severity of CVE-2022-2040?
The severity of CVE-2022-2040 is medium with a severity value of 5.4.
3
What does the Brizy WordPress plugin vulnerability allow an attacker to do?
The Brizy WordPress plugin vulnerability allows users with a role as low as Contributor to perform Stored Cross-Site Scripting (XSS) attacks.
4
Which version of the Brizy WordPress plugin is affected by CVE-2022-2040?
The Brizy WordPress plugin versions before 2.4.2 are affected by CVE-2022-2040.
5
How can I fix the Brizy WordPress plugin vulnerability?
To fix the Brizy WordPress plugin vulnerability, update the plugin to version 2.4.2 or newer.