These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The Themify Builder plugin for WordPress has a Stored Cross-Site Scripting vulnerability via the 'css[fonts]' parameter in versions up to and including 7.8.1. This allows unauthenticated attackers to inject web scripts that execute when a user accesses an injected page. The vulnerability's access control is reduced to a CSRF token due to the nonce being embedded in the front-end page markup.
The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Query Parameter Name in all versions up to, and including, 1.5.5. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
The Themify Builder plugin for WordPress has an authorization bypass vulnerability in all versions up to and including 7.7.7. This vulnerability allows authenticated attackers with subscriber-level access to overwrite or delete generated CSS stylesheet files of arbitrary posts, including private and draft posts, and modify plugin-scoped font options. The required CSRF nonce (tf_nonce) is emitted on public [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. A Cross-site Scripting (XSS) vulnerability exists in Themify Builder plugin for WordPress, specifically in versions from n/a through <= 7.7.4. This issue allows for Reflected XSS attacks due to improper neutralization of input during web page generation. Users of Themify Builder plugin for WordPress, especially those with versions from n/ [truncated]
The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'height_slider' Slider Module Field in all versions up to, and including, 7.7.6. This vulnerability is due to insufficient input sanitization and output escaping, allowing authenticated attackers with contributor-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesse [truncated]
The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Map Module 'b_width_map' Field in all versions up to, and including, 7.7.6. This vulnerability is due to insufficient input sanitization and output escaping, allowing authenticated attackers with contributor-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an [truncated]