Junglewise Threat Intelligence

CVE-2026-57369: themifyme Themify Builder reflected XSS

CVE-2026-57369 · Severity: high · CVSS 7.1 · Published 2026-07-13

Technologies: Themifyme Themify Builder. Vendors: Themify.

Executive brief

Themify Builder, a popular WordPress plugin used for designing website layouts, is vulnerable to a security flaw that allows attackers to execute malicious scripts. By tricking a site administrator or visitor into clicking a specially crafted link, an attacker could hijack user sessions, redirect visitors to malicious websites, or deface the site. This vulnerability poses a risk to site reputation and user data security.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Themify Builder plugin (themify-builder) for WordPress due to improper neutralization of user-supplied input during web page generation. The flaw allows an unauthenticated remote attacker to inject malicious scripts into the web pages served to other users. Exploitation requires a victim to interact with a malicious link or crafted page (User Interaction required). Successful exploitation can lead to session hijacking, unauthorized actions in the context of the victim's browser, or delivery of secondary payloads. The issue is fixed in version 7.7.5.

Affected products

  • themifyme Themify Builder <= 7.7.4

Timeline

  • 2026-06-09: disclosed: Reported by Ananda Dhakal via Patchstack
  • 2026-07-07: advisory: Patchstack advisory published
  • 2026-07-13: advisory: NVD published date
  • 2026-07-07: patched: Version 7.7.5 released to address the issue

References

Related threats