CVE-2022-2041: Brizy Page Builder < 2.4.2 - Contributor+ Stored Cross-Site Scripting via Element Content
The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element content, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-2041?
CVE-2022-2041 is a vulnerability in the Brizy WordPress plugin before version 2.4.2 that allows users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.
How severe is CVE-2022-2041?
CVE-2022-2041 has a severity score of 5.4 out of 10, which is considered medium.
What software is affected by CVE-2022-2041?
The Brizy WordPress plugin versions up to 2.4.2 are affected by CVE-2022-2041.
How can I fix CVE-2022-2041?
To fix CVE-2022-2041, update the Brizy WordPress plugin to version 2.4.2 or higher.
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-2041?
The CWE ID for CVE-2022-2041 is CWE-79, which represents Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').