CVE-2024-6254: Brizy – Page Builder <= 2.5.1 - Cross-Site Request Forgery
The Brizy – Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.1. This is due to missing or incorrect nonce validation on form submissions. This makes it possible for unauthenticated attackers to submit forms intended for public use as another user via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. On sites where unfilteredhtml is enabled, this can lead to the admin unknowingly adding a Stored Cross-Site Scripting payload.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6254?
CVE-2024-6254 is classified as a moderate severity vulnerability, allowing unauthenticated attackers to exploit Cross-Site Request Forgery.
How do I fix CVE-2024-6254?
To fix CVE-2024-6254, update the Brizy Page Builder plugin to version 2.5.2 or higher which includes the necessary nonce validation.
Which versions of Brizy Page Builder are affected by CVE-2024-6254?
CVE-2024-6254 affects all versions of Brizy Page Builder up to and including version 2.5.1.
What type of vulnerability is CVE-2024-6254?
CVE-2024-6254 is a Cross-Site Request Forgery (CSRF) vulnerability.
Who can exploit CVE-2024-6254?
CVE-2024-6254 can be exploited by unauthenticated attackers due to the lack of nonce validation.