CVE-2025-32198: WordPress Brizy plugin <= 2.7.7 - Cross Site Scripting (XSS) vulnerability
Published Apr 10, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themefusecom Brizy brizy.This issue affects Brizy: from n/a through <= 2.7.7.
Affected Software
3 affected components
themefuse Brizy<=2.6.14
WordPress Brizy plugin<=2.6.14
Brizy Brizy WordPress<=2.6.14
Event History
Apr 10, 2025
CVE Published
via MITRE·08:09 AM
Data Sourced
via MITRE·08:09 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Sep 23, 58279
Event
via MITRE·07:15 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-32198?
CVE-2025-32198 has a medium severity rating due to its potential to facilitate cross-site scripting attacks.
2
How do I fix CVE-2025-32198?
To fix CVE-2025-32198, update the Brizy plugin to the latest version beyond 2.6.14.
3
What software is affected by CVE-2025-32198?
CVE-2025-32198 affects the Brizy theme and the Brizy plugin for WordPress up to and including version 2.6.14.
4
What type of vulnerability is CVE-2025-32198?
CVE-2025-32198 is classified as a cross-site scripting (XSS) vulnerability.
5
Can CVE-2025-32198 be exploited remotely?
Yes, CVE-2025-32198 can be exploited remotely by attackers through malicious web page injection.