Brizy

Brizy-page Builder

3 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.17%
  • Veröffentlicht 14.10.2021 16:15:09
  • Zuletzt bearbeitet 21.11.2024 06:16:51

The Brizy Page Builder plugin <= 2.3.11 for WordPress was vulnerable to stored XSS by lower-privileged users such as a subscribers. It was possible to add malicious JavaScript to a page by modifying the request sent to update the page via the brizy_u...

  • EPSS 0.25%
  • Veröffentlicht 14.10.2021 16:15:09
  • Zuletzt bearbeitet 21.11.2024 06:16:51

The Brizy Page Builder plugin <= 2.3.11 for WordPress used an incorrect authorization check that allowed any logged-in user accessing any endpoint in the wp-admin directory to modify the content of any existing post or page created with the Brizy edi...

  • EPSS 2.28%
  • Veröffentlicht 14.10.2021 16:15:09
  • Zuletzt bearbeitet 21.11.2024 06:16:51

The Brizy Page Builder plugin <= 2.3.11 for WordPress allowed authenticated users to upload executable files to a location of their choice using the brizy_create_block_screenshot AJAX action. The file would be named using the id parameter, which coul...