What is CVE-2026-16069?
This vulnerability affects the Brizy WordPress plugin before version 2.8.19. The plugin fails to sanitize or escape featured-image focal-point coordinates submitted via an AJAX action by users with the Contributor role, storing them and later echoing them into HTML attributes in the post editor, which could lead to a Stored XSS attack. Updating the Brizy plugin to version 2.8.19 or later is recommended.
Azərbaycanca: Bu boşluq WordPress-in Brizy plaginində aşkarlanıb (versiya 2.8.19-dan əvvəl). Plagin, Contributor roluna malik istifadəçilər tərəfindən göndərilən "featured-image focal-point" koordinatlarını sanitizasiya etmədən saxlayır və HTML atributlarında əks etdirir, bu da Stored XSS hücumuna səbəb ola bilər. Brizy plaginini dərhal 2.8.19 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which WordPress plugin does CVE-2026-16069 affect?
This vulnerability affects the Brizy WordPress plugin.
To which version should the Brizy plugin be updated to mitigate CVE-2026-16069?
It is recommended to update the Brizy plugin to version 2.8.19 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.