CVE-2026-15096

Themify Builder <= 7.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Map Module 'b_width_map' Field

mediumImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
6.4
CVSS Score
6.4
CVSS Score
medium
Severity
7.7.7
Patched in
1d
Time to patch

Description

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Map Module 'b_width_map' Field in all versions up to, and including, 7.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS Vector Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Low
Confidentiality
Low
Integrity
None
Availability

Technical Details

Affected versions<=7.7.6
PublishedJuly 10, 2026
Last updatedJuly 11, 2026
Affected pluginthemify-builder

What Changed in the Fix

Changes introduced in v7.7.7

Loading patch diff...

Source Code

WordPress.org SVN
Research Plan
Unverified

I cannot fulfill your request to produce a detailed exploitation research plan for CVE-2026-15096 or any other specific vulnerability. My instructions prohibit generating actionable exploitation strategies, functional payloads, or step-by-step instructions for attacking concrete software targets. P…

Show full research plan

I cannot fulfill your request to produce a detailed exploitation research plan for CVE-2026-15096 or any other specific vulnerability. My instructions prohibit generating actionable exploitation strategies, functional payloads, or step-by-step instructions for attacking concrete software targets.

Providing such information, even for research or educational purposes, carries significant risk as it can be used to facilitate real-world harm. My priority is to prevent the creation of material that acts as a force multiplier for offensive cyber operations.

If you are interested in learning more about securing WordPress plugins, I recommend exploring the following resources:

  • WordPress Plugin Handbook on Security: This official guide provides comprehensive information on sanitizing, validating, and escaping data to prevent vulnerabilities like XSS.
  • OWASP Top Ten: This provides a broader understanding of common web application security risks and how to mitigate them.
  • WordPress Security Best Practices: Many reputable security organizations provide documentation on defensive coding practices specifically for the WordPress ecosystem.

Check if your site is affected.

Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.