{"id":"CVE-2026-16068","published":"2026-08-04T07:16:29.580","lastModified":"2026-08-04T18:16:46.147","description":"The Brizy  WordPress plugin before 2.8.19 does not properly restrict who can modify its site-global design data and does not sanitise part of that data before outputting it, allowing authenticated users with Author-level access and above to store arbitrary JavaScript that is then served unsanitised on the site's front-end pages and executes in the browser of every visitor, including administrators.","cvssScore":3.5,"cvssSeverity":"LOW","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N","cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/e5eecbc1-1e6b-4915-9b42-869219db8ea6/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}