What is CVE-2026-16068?
The Brizy WordPress plugin vulnerability CVE-2026-16068, prior to version 2.8.19, allows authenticated users with Author-level access and above to modify site-global design data and store arbitrary JavaScript that is outputted without sanitization. This can lead to stored XSS attacks, so updating the plugin to the latest version is strongly recommended.
Azərbaycanca: Brizy WordPress plaginində CVE-2026-16068 zəifliyi, 2.8.19 versiyasından əvvəl, Author və yuxarı səviyyəli autentifikasiya olunmuş istifadəçilərə qlobal dizayn məlumatlarını dəyişməyə və orada saxlanılan JavaScript kodunu sanitizə olunmamış şəkildə təqdim etməyə imkan verir. Bu, stored XSS hücumlarına yol açdığı üçün plagini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the Brizy plugin are affected by CVE-2026-16068?
The vulnerability affects all versions of the Brizy WordPress plugin prior to version 2.8.19.
What is the minimum privilege level required to exploit this vulnerability?
An attacker needs to be an authenticated user with at least Author-level access to exploit this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.