plugin

Themify Builder Vulnerabilities

15 known security issues reported for the Themify Builder WordPress plugin. Most recent disclosed Aug 21, 2026.

2 high 13 medium

Running Themify Builder on your site? Check whether your installed version is affected.

Scan your site free

Themify Builder <= 7.8.0 - Missing Authorization to Unauthenticated Arbitrary Builder Data Modification via 'tb_update_old_data' AJAX Action

medium

The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify the stored Themify Builder styling d...

CVSS:
5.3
Affected:
up to 7.8.0
Fixed in:
7.8.1
Disclosed:
Aug 21, 2026

CVE-2026-75027 on NVD →

Themify Builder <= 7.7.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Stylesheet Write/Delete via tb_generate_on_fly AJAX Action

medium

The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.7.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to over...

CVSS:
4.3
Affected:
up to 7.7.7
Fixed in:
7.7.8
Disclosed:
Jul 15, 2026

CVE-2026-15407 on NVD →

Themify Builder <= 7.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Map Module 'b_width_map' Field

medium

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Map Module 'b_width_map' Field in all versions up to, and including, 7.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to...

CVSS:
6.4
Affected:
up to 7.7.6
Fixed in:
7.7.7
Disclosed:
Jul 10, 2026

CVE-2026-15096 on NVD →

Themify Builder <= 7.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'height_slider' Slider Module Field

medium

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'height_slider' Slider Module Field in all versions up to, and including, 7.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and abov...

CVSS:
6.4
Affected:
up to 7.7.6
Fixed in:
7.7.7
Disclosed:
Jul 10, 2026

CVE-2026-15097 on NVD →

Themify Builder <= 7.7.4 - Unauthenticated Stored Cross-Site Scripting

high

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user access...

CVSS:
7.2
Affected:
up to 7.7.4
Fixed in:
7.7.5
Disclosed:
Jul 7, 2026

CVE-2026-57369 on NVD →

Themify Builder <= 7.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 7.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbi...

CVSS:
6.4
Affected:
up to 7.6.9
Fixed in:
7.7.0
Disclosed:
Sep 23, 2025

CVE-2025-9353 on NVD →

Themify Builder <= 7.6.7 - Missing Authorization

medium

The Themify Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.6.7. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 7.6.7
Fixed in:
7.6.8
Disclosed:
Aug 20, 2025

CVE-2025-49396 on NVD →

Themify Builder <= 7.6.5 - Reflected Cross-Site Scripting

medium

The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 7.6.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they...

CVSS:
6.1
Affected:
up to 7.6.5
Fixed in:
7.6.6
Disclosed:
Jan 21, 2025

CVE-2024-13319 on NVD →

Themify Builder <= 7.6.3 - Authenticated (Contributor+) Local File Inclusion

high

The Themify Builder plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.6.3. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files...

CVSS:
8.8
Affected:
up to 7.6.3
Fixed in:
7.6.5
Disclosed:
Dec 19, 2024

CVE-2024-56216 on NVD →

Themify Builder <= 7.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages...

CVSS:
6.4
Affected:
up to 7.6.5
Fixed in:
7.6.6
Disclosed:
Nov 13, 2024

CVE-2024-52423 on NVD →

Themify Builder <= 7.6.2 - Reflected Cross-Site Scripting

medium

The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 7.6.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they...

CVSS:
6.1
Affected:
up to 7.6.2
Fixed in:
7.6.3
Disclosed:
Oct 4, 2024

CVE-2024-9385 on NVD →

Themify Builder <= 7.6.1 - Missing Authorization to Authenticated (Contributor+) Post Duplication

medium

The Themify Builder plugin for WordPress is vulnerable to unauthorized post duplication due to missing checks on the duplicate_page_ajaxify function in all versions up to, and including, 7.6.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to duplicate and view private or...

CVSS:
4.3
Affected:
up to 7.6.1
Fixed in:
7.6.2
Disclosed:
Aug 21, 2024

CVE-2024-7836 on NVD →

Themify Builder <= 7.5.7 - Open Redirect via 'tb_redirect_fail'

medium

The Themify Builder plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 7.5.7. This is due to insufficient validation on the redirect url supplied via the 'tb_redirect_fail' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious s...

CVSS:
6.1
Affected:
up to 7.5.7
Fixed in:
7.5.8
Disclosed:
May 23, 2024

CVE-2024-3032 on NVD →

Themify Builder <= 7.0.5 - Cross-Site Request Forgery

medium

The Themify Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.0.5. This is due to missing or incorrect nonce validation on the cache_menu() function. This makes it possible for unauthenticated attackers to clear cache via a forged request granted they can trick...

CVSS:
4.3
Affected:
up to 7.0.5
Fixed in:
7.0.6
Disclosed:
Feb 5, 2024

CVE-2024-24872 on NVD →

Themify Builder <= 5.3.1 - Reflected Cross-Site Scripting

medium

The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the multiple parameters in versions up to, and including, 5.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exec...

CVSS:
6.1
Affected:
up to 5.3.1
Fixed in:
5.3.2
Disclosed:
Oct 4, 2021

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database