Themify

Themify Builder

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 16.07.2026 07:51:04
  • Zuletzt bearbeitet 18.07.2026 03:16:35

The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.7.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for au...

  • EPSS 0.18%
  • Veröffentlicht 13.07.2026 08:41:23
  • Zuletzt bearbeitet 13.07.2026 16:57:56

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Builder themify-builder allows Reflected XSS.This issue affects Themify Builder: from n/a through <= 7.7.4.

  • EPSS 0.19%
  • Veröffentlicht 11.07.2026 03:44:23
  • Zuletzt bearbeitet 13.07.2026 17:17:03

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Map Module 'b_width_map' Field in all versions up to, and including, 7.7.6 due to insufficient input sanitization and output escaping. This makes it possible fo...

  • EPSS 0.2%
  • Veröffentlicht 11.07.2026 03:44:20
  • Zuletzt bearbeitet 15.07.2026 14:17:17

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'height_slider' Slider Module Field in all versions up to, and including, 7.7.6 due to insufficient input sanitization and output escaping. This makes it possib...

  • EPSS 0.3%
  • Veröffentlicht 24.09.2025 13:15:37
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 7.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authentica...

  • EPSS 0.29%
  • Veröffentlicht 22.01.2025 08:15:08
  • Zuletzt bearbeitet 24.01.2025 21:06:34

The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 7.6.5. This makes it possible for unauthenticated a...