PT-2026-79503 · WordPress · Themify Builder

·

CVE-2026-75027

·

Published

2026-08-22

·

Updated

2026-08-24

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Themify Builder versions prior to 7.8.1
Description The plugin fails to properly verify user authorization when performing certain actions. This allows unauthenticated attackers to modify stored styling data, specifically padding and margin properties, of arbitrary posts, including those marked as private or drafts. The attack is executed by providing a controlled post ID and a JSON styling payload to the tb update old data AJAX action. Because the required nonce is automatically emitted to all frontend pages via wp localize script, any visitor can retrieve it from the page source to bypass the existing access control.
Recommendations Update the plugin to a version newer than 7.8.0. As a temporary mitigation, restrict access to the tb update old data AJAX action.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75027

Affected Products

Themify Builder