Executive brief
Themify Builder, a popular page-building tool for WordPress, contains a security flaw that allows low-level users (like subscribers) to interfere with website design settings. An attacker can delete or overwrite the styling files for any post, including private drafts, and change global font settings. This could lead to unauthorized visual changes or the disruption of website content.
Technical details
The Themify Builder plugin for WordPress suffers from a missing authorization check (CWE-862) in its stylesheet management logic. Authenticated attackers with subscriber-level permissions or higher can exploit this to overwrite or delete generated CSS files for any post, including private or draft posts, and modify plugin-scoped font options. The attack is facilitated by the fact that the required CSRF nonce (tf_nonce) is exposed on public front-end pages via wp_localize_script, making it easily accessible to any logged-in user. The vulnerability is present in all versions up to and including 7.7.7.
Affected products
- Themify Themify Builder <= 7.7.7
Timeline
- 2026-07-16: disclosed
- 2026-07-16: advisory
References
- https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.7.5/classes/class-themify-builder-stylesheet.php
- https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.7.5/classes/class-themify-builder-stylesheet.php
- https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.7.5/classes/class-themify-builder-stylesheet.php
- https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.7.5/classes/class-themify-builder-stylesheet.php
- https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.7.7/classes/class-themify-builder-stylesheet.php
- https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.7.7/classes/class-themify-builder-stylesheet.php
- https://plugins.trac.wordpress.org/browser/themify-builder/tags/7.7.7/classes/class-themify-builder-stylesheet.php