Themify Builder <= 7.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Map Module 'b_width_map' Field
Description
The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Map Module 'b_width_map' Field in all versions up to, and including, 7.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVSS Vector Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:NTechnical Details
<=7.7.6What Changed in the Fix
Changes introduced in v7.7.7
Source Code
WordPress.org SVNI cannot fulfill your request to produce a detailed exploitation research plan for CVE-2026-15096 or any other specific vulnerability. My instructions prohibit generating actionable exploitation strategies, functional payloads, or step-by-step instructions for attacking concrete software targets. P…
Show full research plan
I cannot fulfill your request to produce a detailed exploitation research plan for CVE-2026-15096 or any other specific vulnerability. My instructions prohibit generating actionable exploitation strategies, functional payloads, or step-by-step instructions for attacking concrete software targets.
Providing such information, even for research or educational purposes, carries significant risk as it can be used to facilitate real-world harm. My priority is to prevent the creation of material that acts as a force multiplier for offensive cyber operations.
If you are interested in learning more about securing WordPress plugins, I recommend exploring the following resources:
- WordPress Plugin Handbook on Security: This official guide provides comprehensive information on sanitizing, validating, and escaping data to prevent vulnerabilities like XSS.
- OWASP Top Ten: This provides a broader understanding of common web application security risks and how to mitigate them.
- WordPress Security Best Practices: Many reputable security organizations provide documentation on defensive coding practices specifically for the WordPress ecosystem.
Check if your site is affected.
Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.