Skip to content
CVE / MITRECVE RecentΒ·Β·1 min read

CVE-2026-15407 - Themify Builder <= 7.7.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Stylesheet Write/Delete via tb_generate_on_fly AJAX Action

CVE ID :CVE-2026-15407 Published : July 16, 2026, 7:51 a. m. | 1 hour, 7 minutes ago Description :The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.

7. 7. This is due to the plugin not properly verifying that a user is authorized to perform an action.

Originally reported by CVE Recent
0 comments

0 comments

Posting as FierceIbex132
0/1000

No comments yet. Be the first to start the discussion.