PT-2021-22064 · WordPress · Brizy – Page Builder
Ramuel Gall
·
Published
2021-10-14
·
Updated
2022-07-05
·
CVE-2021-38344
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Brizy Page Builder plugin versions <= 2.3.11
Description
The issue allows lower-privileged users, such as subscribers, to perform stored XSS attacks. This is achieved by modifying the request sent to update a page via the
brizy update item AJAX action and adding malicious JavaScript to the data parameter. The added JavaScript is executed in the session of any visitor who views or previews the post or page.Recommendations
For Brizy Page Builder plugin versions <= 2.3.11, update to a version higher than 2.3.11 to resolve the issue. As a temporary workaround, consider restricting access to the
brizy update item AJAX action to prevent exploitation. Additionally, restrict the ability of lower-privileged users to update pages until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Brizy – Page Builder