CVE-2024-6254

The Brizy – Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.1. This is due to missing or incorrect nonce validation on form submissions. This makes it possible for unauthenticated attackers to submit forms intended for public use as another user via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. On sites where unfiltered_html is enabled, this can lead to the admin unknowingly adding a Stored Cross-Site Scripting payload.
Configurations

Configuration 1 (hide)

cpe:2.3:a:brizy:brizy:*:*:*:*:-:wordpress:*:*

History

01 Mar 2025, 01:20

Type Values Removed Values Added
First Time Brizy
Brizy brizy
References () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3129495%40brizy%2Ftrunk&old=3125955%40brizy%2Ftrunk&sfp_email=&sfph_mail= - () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3129495%40brizy%2Ftrunk&old=3125955%40brizy%2Ftrunk&sfp_email=&sfph_mail= - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/75ec04f1-8bea-4514-b1d0-da5b305219d7?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/75ec04f1-8bea-4514-b1d0-da5b305219d7?source=cve - Third Party Advisory
CWE CWE-79
CPE cpe:2.3:a:brizy:brizy:*:*:*:*:-:wordpress:*:*

Information

Published : 2024-08-08 04:17

Updated : 2025-03-01 01:20


NVD link : CVE-2024-6254

Mitre link : CVE-2024-6254

CVE.ORG link : CVE-2024-6254


JSON object : View

Products Affected

brizy

  • brizy
CWE
CWE-20

Improper Input Validation

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')