CVE-2025-9353: Themify Builder <= 7.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 7.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 7.6.9.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9353?
CVE-2025-9353 is classified as a high severity vulnerability due to its potential for exploitation via stored cross-site scripting.
How do I fix CVE-2025-9353?
To fix CVE-2025-9353, update the Themify Builder plugin to version 7.7 or later, which includes necessary security patches.
Who is affected by CVE-2025-9353?
CVE-2025-9353 affects all versions of the Themify Builder plugin for WordPress up to and including version 7.6.9.
What kind of attack does CVE-2025-9353 enable?
CVE-2025-9353 enables authenticated attackers to perform stored cross-site scripting attacks, which can compromise user sessions or redirect users.
Is user interaction required for CVE-2025-9353 exploitation?
Yes, user interaction is required for exploitation of CVE-2025-9353, as it involves authenticated access to launch the attack.