CVE-2026-15407
- EPSS 0.29%
- Veröffentlicht 16.07.2026 07:51:04
- Zuletzt bearbeitet 18.07.2026 03:16:35
The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.7.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for au...
CVE-2026-57369
- EPSS 0.18%
- Veröffentlicht 13.07.2026 08:41:23
- Zuletzt bearbeitet 13.07.2026 16:57:56
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Builder themify-builder allows Reflected XSS.This issue affects Themify Builder: from n/a through <= 7.7.4.
CVE-2026-15096
- EPSS 0.19%
- Veröffentlicht 11.07.2026 03:44:23
- Zuletzt bearbeitet 13.07.2026 17:17:03
The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Map Module 'b_width_map' Field in all versions up to, and including, 7.7.6 due to insufficient input sanitization and output escaping. This makes it possible fo...
CVE-2026-15097
- EPSS 0.2%
- Veröffentlicht 11.07.2026 03:44:20
- Zuletzt bearbeitet 15.07.2026 14:17:17
The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'height_slider' Slider Module Field in all versions up to, and including, 7.7.6 due to insufficient input sanitization and output escaping. This makes it possib...
CVE-2025-9353
- EPSS 0.3%
- Veröffentlicht 24.09.2025 13:15:37
- Zuletzt bearbeitet 15.04.2026 00:35:42
The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 7.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authentica...
CVE-2024-13319
- EPSS 0.29%
- Veröffentlicht 22.01.2025 08:15:08
- Zuletzt bearbeitet 24.01.2025 21:06:34
The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 7.6.5. This makes it possible for unauthenticated a...