Themify Builder

Themify Builder has 15 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2026; all 15 are fixed as of September 2026. Their average CVSS score is 5.9, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 2 high. 2024 was the busiest year with 6 disclosures.

The most common weakness is Cross-Site Scripting, behind 8 of the records (53%). Other recurring categories include Missing Authorization, Cross-Site Request Forgery (CSRF).

Every one of the 15 issues recorded for Themify Builder has a vendor fix available, so running the current release closes all known holes.

10 independent researchers contributed these findings, most of them (4) reported by Wordfence PRISM. Themify Builder is installed on roughly 5,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

01234567891011.12.2018Today04.10.20216.1Themify Builder <= 5.3.1 - Reflected Cross-Site Scripting CVSS 6.1 · 04.10.202105.02.20244.3Themify Builder <= 7.0.5 - Cross-Site Request Forgery CVSS 4.3 · 05.02.202423.05.20246.1Themify Builder <= 7.5.7 - Open Redirect via 'tb_redirect_fail' CVSS 6.1 · 23.05.202421.08.20244.3Themify Builder <= 7.6.1 - Missing Authorization to Authenticated (Contributor+) Post Duplication CVSS 4.3 · 21.08.202404.10.20246.1Themify Builder <= 7.6.2 - Reflected Cross-Site Scripting CVSS 6.1 · 04.10.202413.11.20246.4Themify Builder <= 7.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 13.11.202419.12.20248.8Themify Builder <= 7.6.3 - Authenticated (Contributor+) Local File Inclusion CVSS 8.8 · 19.12.202421.01.20256.1Themify Builder <= 7.6.5 - Reflected Cross-Site Scripting CVSS 6.1 · 21.01.202520.08.20254.3Themify Builder <= 7.6.7 - Missing Authorization CVSS 4.3 · 20.08.202523.09.20256.4Themify Builder <= 7.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 23.09.202507.07.20267.2Themify Builder <= 7.7.4 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 07.07.202610.07.20266.4Themify Builder <= 7.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'height_slider' Slider Module Field CVSS 6.4 · 10.07.20266.4Themify Builder <= 7.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Map Module 'b_width_map' Field CVSS 6.4 · 10.07.202615.07.20264.3Themify Builder <= 7.7.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Stylesheet Write/Delete via tb_generate_on_fly AJAX Action CVSS 4.3 · 15.07.202621.08.20265.3Themify Builder <= 7.8.0 - Missing Authorization to Unauthenticated Arbitrary Builder Data Modification via 'tb_update_old_data' AJAX Action CVSS 5.3 · 21.08.2026

Strategic Overview

Avg CVSSMedium
5.9/ 10
Patch Coverage100%
Open

0

Fixed

15

Get automatic notifications for all Themify Builder vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2024-56216

Themify Builder <= 7.6.3 - Authenticated (Contributor+) Local File Inclusion

Read the full analysis

Vulnerability Records

15 records
2026-08-21 15:10CVE-2026-75027
5.3
Medium
Wordfence PRISMYes
2026-07-15 00:00CVE-2026-15407
4.3
Medium
Wordfence PRISMYes
2026-07-10 15:32CVE-2026-15096
6.4
Medium
Wordfence PRISMYes
2026-07-10 15:31CVE-2026-15097
6.4
Medium
Wordfence PRISMYes
2026-07-07 00:00CVE-2026-57369
7.2
High
Ananda DhakalYes
2025-09-23 00:00CVE-2025-9353
6.4
Medium
zer0gh0stYes
2025-08-20 00:00CVE-2025-49396
4.3
Medium
Denver JacksonYes
2025-01-21 00:00CVE-2024-13319
6.1
Medium
Colin XuYes
2024-12-19 00:00CVE-2024-56216
8.8
High
João Pedro Soares de AlcântaraYes
2024-11-13 00:00CVE-2024-52423
6.4
Medium
João Pedro Soares de AlcântaraYes
Showing 1–10 of 15 reports
Themify Builder banner
Latestv7.8.1

Themify Builder

themifyme

Author

themifyme

3.9(24)
78/100
Last Updated
2026-08-19 (25d ago)
Active Installs
5,000+
Downloads
659,791
Requires WP
5.2+
Requires PHP
7.4+
Tested up to
WP 7.0.4
Created
2018-12-11 (8y ago)

The Themify Builder is the most powerful and easy to use page designer and builder for WordPress. Design any layout that you can imagine with its drag and drop interface, and with live preview, you can see everything come together right in front of your eyes. Simply select, drag and drop, and you’ve built beautiful pages – without any coding! The Builder is modular in design and is optimized for better performance resources. It’s also SEO friendly, translatable, and supports multi-site networks. In addition, it comes with its own cache system that reduces the server resources and process processes pages faster. Works on any post type, support HTML input, and play well with all major plugins such as WooCommerce, SEO Yoast, Disqus, MailChimp, Jetpack, WPML, and Contact Form 7. Themify Builder – Overview Builder Features: Responsive across all resolutions. Frontend live preview editing. Compact backend Builder editing. Includes all modules (Text, Video, Accordion, Gallery, Post, Widgetized, Widget, Menu, Button, Slider, Map, Icon, Feature, etc.) Custom styling – Google fonts, background color, padding, margin, and border. Undo/Redo Builder modifications as you edit. Copy/Paste modules, rows, and columns. Import/Export specific modules, rows, and columns from one computer to another. Easily duplicate any module or row. Row and column layout pre-set grids. Rows and columns can be nested in sub rows or columns. Draggable column widths. 60+ predesigned Builder layouts. 60+ animation effects. Responsive Styling. Background – slider, video, parallax scrolling, and gradient. Revisions – allows you to save your Builder layout with unlimited versions. Visibility control where you can set whether a module or row is visible on a specific device. Layout parts – re-usable parts that can be included in the Builder. Custom CSS

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C