Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-75027— Themify Builder <= 7.8.0 - Missing Authorization to Unauthenticated Arbitrary Builder Data Modification via 'tb_update_old_data' AJAX Action

Quick assessment

Affected
themifyme Themify Builder
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 中的 Themify Builder 插件在所有不高于 7.8.0 的版本中存在身份验证绕过漏洞。该漏洞是由于插件未能正确验证用户是否具有执行操作的权限所致。攻击者可以通过提供其控制的帖子 ID 和 JSON 样式的载荷,未经授权地修改任意帖子(包括私有帖子和草稿)中存储的 Themify Builder 样式数据(填充和内边距属性)。由于处理程序所需的 nonce(一次性令牌)会通过 函数自动发布到所有由构建器渲染的前端页面,因此任何未认证的用户都可以从页面源代码中轻松获取有效的 nonce,

CVSS 5.3 · Medium EPSS 0.34% · P27

Affected Version Matrix 1

VendorProduct Version RangeStatus
themifyme Themify Builder ≤ 7.8.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-75027

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Themify Builder <= 7.8.0 - Missing Authorization to Unauthenticated Arbitrary Builder Data Modification via 'tb_update_old_data' AJAX Action
Source: CVE Program / CVE List V5
Vulnerability Description
The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify the stored Themify Builder styling data (padding and margin properties) of arbitrary posts, including private and draft posts, by supplying an attacker-controlled post ID and JSON styling payload. The nonce required by the handler is automatically emitted to all frontend pages rendered by the builder via wp_localize_script, meaning any unauthenticated visitor can trivially retrieve a valid nonce from page source and satisfy the only access control in place.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
themifyme Themify Builder 0 ~ 7.8.0 -

II. Public POCs for CVE-2026-75027

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-75027

登录查看更多情报信息。

News Coverage for CVE-2026-75027 (1)

Other References for CVE-2026-75027 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-75027

No comments yet


Leave a comment