PatchSiren

themifyme CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM themifyme CVE published 2026-07-16

CVE-2026-15407

The Themify Builder plugin for WordPress has an authorization bypass vulnerability in all versions up to and including 7.7.7. This vulnerability allows authenticated attackers with subscriber-level access to overwrite or delete generated CSS stylesheet files of arbitrary posts, including private and draft posts, and modify plugin-scoped font options. The required CSRF nonce (tf_nonce) is emitted on public [truncated]

HIGH themifyme CVE published 2026-07-13

CVE-2026-57369

AI-assisted PatchSiren debrief based on the supplied source corpus. A Cross-site Scripting (XSS) vulnerability exists in Themify Builder plugin for WordPress, specifically in versions from n/a through <= 7.7.4. This issue allows for Reflected XSS attacks due to improper neutralization of input during web page generation. Users of Themify Builder plugin for WordPress, especially those with versions from n/ [truncated]

MEDIUM themifyme CVE published 2026-07-11

CVE-2026-15097

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'height_slider' Slider Module Field in all versions up to, and including, 7.7.6. This vulnerability is due to insufficient input sanitization and output escaping, allowing authenticated attackers with contributor-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesse [truncated]

MEDIUM themifyme CVE published 2026-07-11

CVE-2026-15096

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Map Module 'b_width_map' Field in all versions up to, and including, 7.7.6. This vulnerability is due to insufficient input sanitization and output escaping, allowing authenticated attackers with contributor-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an [truncated]