Where
-Infinity
0

Themify Themify BuilderThemify Builder <= 7.7.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Stylesheet Write/Delete via tb_generate_on_fly AJAX Action

Risk 22
Severity
4.3
First published (updated )

Themify Themify BuilderWordPress Themify Builder plugin <= 7.7.4 - Cross Site Scripting (XSS) vulnerability

Risk 50
Severity
7.1
First published (updated )

Themify Themify BuilderThemify Builder <= 7.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Map Module 'b_width_map' Field

Risk 39
Severity
6.4
First published (updated )

Themify Themify Builder (WordPress plugin)Themify Builder <= 7.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'height_slider' Slider Module Field

Risk 39
Severity
6.4
First published (updated )

Themify Themify FoloWordPress Themify Folo theme <= 1.9.6 - Reflected Cross Site Scripting (XSS) vulnerability

Risk 50
Severity
7.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Themify Themify Event PostWordPress Themify Event Post plugin <= 1.3.4 - Cross Site Scripting (XSS) vulnerability

Risk 34
Severity
6.5
EPSS
0.03%
First published (updated )

Themify Sidepane WordPress ThemeWordPress Themify Newsy <= 1.9.9 - Arbitrary File Upload Vulnerability

Risk 82
Severity
9.9
First published (updated )

Themify ShopoWordPress Shopo <= 1.1.4 - Arbitrary File Upload Vulnerability

Risk 82
Severity
9.9
First published (updated )

Themify Themify EdminWordPress Themify Edmin theme <= 2.0.0 - PHP Object Injection Vulnerability

Risk 79
Severity
8.8
First published (updated )

Themify BuilderThemify Builder <= 7.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

Risk 28
Severity
6.4
EPSS
0.05%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Themify Themify PopupWordPress Themify Popup Plugin <= 1.4.2 - Cross Site Scripting (XSS) Vulnerability

Risk 46
Severity
6.5
First published (updated )

Themify Themify IconsWordPress Themify Icons Plugin <= 2.0.3 - Cross Site Scripting (XSS) Vulnerability

Risk 46
Severity
6.5
First published (updated )

Themify Themify Event PostWordPress Themify Event Post Plugin <= 1.3.2 - Local File Inclusion vulnerability

Risk 30
Severity
7.5
EPSS
0.13%
First published (updated )

Themify BuilderThemify Builder <= 7.6.5 - Reflected Cross-Site Scripting

Risk 38
Severity
6.1
First published (updated )

Themify Builder WordPressWordPress Themify Builder plugin <= 7.6.3 - Local File Inclusion vulnerability

Risk 38
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Themify Store LocatorThemify Store Locator <= 1.1.9 - Cross-Site Request Forgery

Risk 22
Severity
4.3
First published (updated )

Themify Builder WordPressWordPress Themify Builder plugin <= 7.6.5 - Cross Site Scripting (XSS) vulnerability

Risk 34
Severity
6.5
First published (updated )

Themify WooCommerce Product FilterWordPress Themify plugin <= 1.5.1 - Cross Site Scripting (XSS) vulnerability

Risk 29
Severity
5.9
First published (updated )

Themify BuilderThemify Builder <= 7.6.2 - Reflected Cross-Site Scripting

Risk 28
Severity
6.1
EPSS
0.04%
First published (updated )

Themify Builder WordPressThemify Builder <= 7.6.1 - Missing Authorization to Authenticated (Contributor+) Post Duplication

Risk 16
Severity
4.3
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Themify Themify ShortcodesWordPress Themify Shortcodes plugin <= 2.1.1 - Cross Site Scripting (XSS) vulnerability

Risk 46
Severity
6.5
First published (updated )

Themify Product Filter WordpressThemify - WooCommerce Product Filter <= 1.4.9 - Unauthenticated SQL Injection via conditions Parameter

Risk 61
Severity
9.8
EPSS
0.06%
First published (updated )

Themify Ultra WordpressWordPress Themify Ultra theme <= 7.3.5 - Multiple Broken Access Control vulnerability

Risk 79
Severity
8.8
First published (updated )

Themify Ultra WordpressWordPress Themify Ultra theme <= 7.3.5 - Authenticated Arbitrary Settings Change vulnerability

Risk 79
Severity
8.8
First published (updated )

Themify Builder WordPressThemify Builder < 7.5.8 - Open Redirect

Risk 38
Severity
6.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Themify Ultra WordpressWordPress Themify Ultra theme <= 7.3.5 - Authenticated Privilege Escalation vulnerability

Risk 79
Severity
8.8
First published (updated )

Themify ShortcodesThemify Shortcodes <= 2.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via themify_button Shortcode

Risk 28
Severity
6.4
EPSS
0.04%
First published (updated )

Themify Post Type Builder (PTB)WordPress Post Type Builder (PTB) plugin <= 2.0.8 - Auth. Arbitrary Post/Page Creation vulnerability

Risk 35
Severity
7.1
EPSS
0.04%
First published (updated )

Themify Post Type BuilderWordPress Post Type Builder (PTB) plugin < 2.1.1 - Reflected Cross Site Scripting (XSS) vulnerability

Risk 36
Severity
7.1
EPSS
0.04%
First published (updated )

Themify WordPress pluginWooCommerce Product Filter < 1.4.4 - Reflected XSS

Risk 29
Severity
4.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203