Extension WordPress
Vulnérabilités Themify Builder
Cette page rassemble les failles publiées pour Themify Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Themify Builder
14 fiches
Themify Builder <= 7.7.7 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Stylesheet Write/Delete via tb_generate_on_fly AJAX Action
The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.7.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This…
*-7.7.7
7.7.8
15/07/2026
Themify Builder <= 7.7.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via Map Module 'b_width_map' Field
The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Map Module 'b_width_map' Field in all versions up to, and including, 7.7.6 due to insufficient input sanitization and output escaping. This makes it possible for…
*-7.7.6
7.7.7
10/07/2026
Themify Builder <= 7.7.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'height_slider' Slider Module Field
The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'height_slider' Slider Module Field in all versions up to, and including, 7.7.6 due to insufficient input sanitization and output escaping. This makes it possible for…
*-7.7.6
7.7.7
10/07/2026
Themify Builder <= 7.7.4 – Unauthenticated Stored Cross-Site Scripting
The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-7.7.4
7.7.5
07/07/2026
Themify Builder <= 7.6.9 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 7.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-7.6.9
7.7.0
23/09/2025
Themify Builder <= 7.6.7 – Missing Authorization
The Themify Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.6.7. This makes it possible for authenticated attackers, with Contributor-level access…
*-7.6.7
7.6.8
20/08/2025
Themify Builder <= 7.6.5 – Reflected Cross-Site Scripting
The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 7.6.5. This makes it possible for unauthenticated…
*-7.6.5
7.6.6
21/01/2025
Themify Builder <= 7.6.3 – Authenticated (Contributor+) Local File Inclusion
The Themify Builder plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.6.3. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on…
*-7.6.3
7.6.5
19/12/2024
Themify Builder <= 7.6.5 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
*-7.6.5
7.6.6
13/11/2024
Themify Builder <= 7.6.2 – Reflected Cross-Site Scripting
The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 7.6.2. This makes it possible for unauthenticated…
*-7.6.2
7.6.3
04/10/2024
Themify Builder <= 7.6.1 – Missing Authorization to Authenticated (Contributor+) Post Duplication
The Themify Builder plugin for WordPress is vulnerable to unauthorized post duplication due to missing checks on the duplicate_page_ajaxify function in all versions up to, and including, 7.6.1. This makes it possible for authenticated attackers, with Contributor-level access…
*-7.6.1
7.6.2
21/08/2024
Themify Builder <= 7.5.7 – Open Redirect via 'tb_redirect_fail'
The Themify Builder plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 7.5.7. This is due to insufficient validation on the redirect url supplied via the 'tb_redirect_fail' parameter. This makes it possible…
*-7.5.7
7.5.8
23/05/2024
Themify Builder <= 7.0.5 – Cross-Site Request Forgery
The Themify Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.0.5. This is due to missing or incorrect nonce validation on the cache_menu() function. This makes it possible for unauthenticated…
*-7.0.5
7.0.6
05/02/2024
Themify Builder <= 5.3.1 – Reflected Cross-Site Scripting
The Themify Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the multiple parameters in versions up to, and including, 5.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
*-5.3.1
5.3.2
04/10/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.