CVE-2021-38344
Last modified
CVE-2021-38344 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. The Brizy Page Builder plugin <= 2.3.11 for WordPress was vulnerable to stored XSS by lower-privileged users such as a subscribers. It was possible to add malicious JavaScript to a page by modifying the request sent to update the page via the brizy_update_item AJAX action and adding JavaScript to the data parameter, which would be executed in the session of any visitor viewing or previewing the post or page.. EPSS estimates a 0.61% chance of exploitation in the next 30 days.
Description
The Brizy Page Builder plugin <= 2.3.11 for WordPress was vulnerable to stored XSS by lower-privileged users such as a subscribers. It was possible to add malicious JavaScript to a page by modifying the request sent to update the page via the brizy_update_item AJAX action and adding JavaScript to the data parameter, which would be executed in the session of any visitor viewing or previewing the post or page.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Brizy | Brizy-Page Builder | <= 2.3.11 |
References
- https://www.wordfence.com/blog/2021/10/multiple-vulnerabilities-in-brizy-page-builder-plugin-allow-site-takeover/Exploit, Third Party Advisory
- https://www.wordfence.com/blog/2021/10/multiple-vulnerabilities-in-brizy-page-builder-plugin-allow-site-takeover/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-38344?
How severe is CVE-2021-38344?
How do I fix CVE-2021-38344?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-38339The Simple Matted Thumbnails WordPress plugin is vulnerable …6.1
- CVE-2021-3834Integria IMS in its 5.0.92 version does not filter correctly…6.1
- CVE-2021-38340The Wordpress Simple Shop WordPress plugin is vulnerable to …6.1
- CVE-2021-38341The WooCommerce Payment Gateway Per Category WordPress plugi…6.1
- CVE-2021-38342The Nested Pages WordPress plugin <= 3.1.15 was vulnerable t…8.1
- CVE-2021-38343The Nested Pages WordPress plugin <= 3.1.15 was vulnerable t…6.1
- CVE-2021-38345The Brizy Page Builder plugin <= 2.3.11 for WordPress used a…6.5
- CVE-2021-38346The Brizy Page Builder plugin <= 2.3.11 for WordPress allowe…8.8
- CVE-2021-38347The Custom Website Data WordPress plugin is vulnerable to Re…6.1
- CVE-2021-38348The Advance Search WordPress plugin is vulnerable to Reflect…6.1
- CVE-2021-38349The Integration of Moneybird for WooCommerce WordPress plugi…6.1
- CVE-2021-3835Buffer overflow in usb device class. Zephyr versions >= v2.6…8.8
Are you affected by CVE-2021-38344?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
