Authorization Bypass in Themify Builder Plugin for WordPress
CVE-2026-75027

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 August 2026

What is CVE-2026-75027?

The Themify Builder plugin for WordPress is vulnerable due to improper authorization checks, allowing unauthenticated attackers to modify styling data of posts, including private and draft content. Attackers can exploit this flaw by supplying a crafted post ID and JSON payload to manipulate padding and margin properties. The nonce verification intended to protect these actions is exposed on all frontend pages, making it easily retrievable by any visitor, thus bypassing access controls.

Affected Version(s)

Themify Builder 0 <= 7.8.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.