Junglewise Threat Intelligence

CVE-2026-15097: Themify Builder Stored XSS in Slider Module height_slider field

CVE-2026-15097 · Severity: medium · CVSS 6.4 · Published 2026-07-11

Technologies: Themify Builder. Vendors: Themify.

Executive brief

The Themify Builder plugin for WordPress, which is used to design and build website layouts, contains a security flaw that allows users with contributor-level access to inject malicious scripts into pages. These scripts will automatically run in the browser of any visitor who views the affected page. This could lead to unauthorized actions being performed on behalf of site visitors or administrators, potentially compromising the website's integrity.

Technical details

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'height_slider' Slider Module field. This vulnerability exists in all versions up to and including 7.7.6. An authenticated attacker with contributor-level permissions or higher can inject arbitrary JavaScript into a page. Because the payload is stored in the database, the script executes in the context of any user's browser session when they visit the compromised page. The issue is tracked as CWE-79 and was addressed in subsequent updates.

Affected products

  • Themify Themify Builder up to, and including, 7.7.6

Timeline

  • 2026-07-11: disclosed
  • 2026-07-11: advisory

References

Related threats