CVE-2024-3667: Brizy – Page Builder <= 2.4.43 - Authenticated (Contributor+) Store Cross-Site Scripting via Widget Link To URL
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Link To' field of multiple widgets in all versions up to, and including, 2.4.43 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3667?
CVE-2024-3667 is classified as a high severity vulnerability due to its potential for exploiting stored cross-site scripting on WordPress sites.
How do I fix CVE-2024-3667?
To fix CVE-2024-3667, update the Brizy Page Builder plugin to version 2.4.44 or newer to ensure proper input sanitization.
What variants of the Brizy Page Builder are affected by CVE-2024-3667?
All versions of the Brizy Page Builder plugin for WordPress up to and including 2.4.43 are affected by CVE-2024-3667.
How does CVE-2024-3667 impact my WordPress site?
CVE-2024-3667 can allow an attacker to execute malicious scripts on your site, potentially compromising user data or site integrity.
Is CVE-2024-3667 specific to certain widgets in Brizy?
Yes, CVE-2024-3667 specifically affects the 'Link To' field in multiple widgets within the Brizy Page Builder plugin.