Extension WordPress
Vulnérabilités Brizy – Page Builder, page 2
Cette page rassemble les failles publiées pour Brizy – Page Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Brizy – Page Builder
31 fiches
Brizy – Page Builder <= 2.4.40 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's block upload in all versions up to, and including, 2.4.40 due to insufficient input sanitization and output escaping on user supplied…
*-2.4.40
2.4.41
23/02/2024
Brizy – Page Builder <= 2.4.39 – Authenticated (Contributor+) Directory Traversal
The Brizy – Page Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.39 via the 'id'. This makes it possible for authenticated attackers, with contributor-level access and above, to upload…
*-2.4.40
2.4.41
23/02/2024
Brizy <= 2.4.29 – Cross-Site Scripting
The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.4.29 due to insufficient input sanitization and output escaping on user supplied attributes.…
*-2.4.29
2.4.30
06/11/2023
Brizy Page Builder <= 2.4.18 – IP Address Spoofing to Protection Mechanism Bypass
The Brizy Page Builder plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.4.18. This is due to an implicit trust of user-supplied IP addresses in an 'X-Forwarded-For' HTTP header for the…
*-2.4.18
2.4.19
31/05/2023
Brizy Page Builder <= 2.4.1 – Authenticated Stored Cross-Site Scripting via Element Content
The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element content, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks
[*, 2.4.2)
2.4.2
21/06/2022
Brizy Page Builder <= 2.4.1 – Authenticated Stored Cross-Site Scripting via Element URL
The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element URL, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks
[*, 2.4.2)
2.4.2
21/06/2022
Brizy Page Builder <= 2.3.11 – Authenticated File Upload and Path Traversal
The Brizy Page Builder plugin
*-2.3.11
2.3.12
13/10/2021
Brizy – Page Builder <= 2.3.11 – Stored Cross-Site Scripting
The Brizy Page Builder plugin
*-2.3.11
2.3.12
13/10/2021
Brizy Page Builder <= 2.3.11 – Incorrect Authorization Checks Allowing Post Modification
The Brizy Page Builder plugin
*-1.0.125, 1.0.127-2.3.11
1.0.126, 2.3.12
13/10/2020
Brizy < 1.0.126 – Authorization Bypass to Settings Updates
The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_administrator() function in versions up to, and including, 1.0.125. This makes it possible for authenticated attackers to access and interact…
[*, 1.0.126)
1.0.126
03/06/2020
Brizy – Page Builder < 1.0.114 – Missing Authorization to Settings Update
The Brizy – Page Builder plugin for WordPress is vulnerable to authorization bypass due to a missing capability check and direct file access to /brizy/admin/site-settings.php in versions up to 1.0.114. This makes it possible for unauthenticated attackers to…
[*, 1.0.114)
1.0.114
05/03/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.