Stored Cross-Site Scripting Vulnerability in Themify Builder Plugin for WordPress
CVE-2026-95864
7.2HIGH
What is CVE-2026-95864?
The Themify Builder plugin for WordPress is susceptible to Stored Cross-Site Scripting through the 'css[fonts]' parameter due to inadequate input sanitization and escaping of output. This vulnerability allows unauthenticated attackers to inject malicious web scripts into pages, which are executed whenever a user accesses an affected page. The nonce required for exploiting this endpoint is easily accessible within the front-end page markup, allowing attackers to circumvent authentication barriers. Consequently, this makes the endpoint vulnerable and exploitable by individuals without proper authentication.
Affected Version(s)
Themify Builder 0 <= 7.8.1