CVE-2026-75027Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify the stored Themify Builder styling data (padding and margin properties) of arbitrary posts, including private and draft posts, by supplying an attacker-controlled post ID and JSON styling payload. The nonce required by the handler is automatically emitted to all frontend pages rendered by the builder via wp_localize_script, meaning any unauthenticated visitor can trivially retrieve a valid nonce from page source and satisfy the only access control in place.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-08-22); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-08-22: 3Mentions · 2026-08-24: 1Technical Details · 2026-08-22: 2Technical Details · 2026-08-24: 108-2208-24
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-223
Disclosure2General1
2026-08-241
Disclosure1
Full discourse4 posts
  • Ciberseguridad LATAM@CibersegLATAM
    Disclosure

    CVE-2026-75027 expone cómo un nonce público convierte una verificación de seguridad en puerta abierta para modificar estilos en cualquier contenido.

    Post summary

    The tweet announces CVE-2026-75027, explaining that a public nonce compromises security checks, allowing style modification across content. No PoC, exploit, or patch information is provided.

    10000101
    22.5K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-75027 The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.8.0. This is due to the plugin not properly ver… https://www.cve.org/CVERecord?id=CVE-2026-75027 ----- Traducción: CVE-2026-75027 El … http://infoflow.cloud`

    Post summary

    Statement announcing an authorization bypass vulnerability (CVE‑2026‑75027) affecting Themify Builder plugin versions up to 7.8.0.

    0000029
    102 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-75027 The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.8.0. This is due to the plugin not properly ver… https://www.cve.org/CVERecord?id=CVE-2026-75027

    Post summary

    The post announces an authorization bypass vulnerability in the Themify Builder WordPress plugin up to version 7.8.0, with no PoC, exploit, or remediation details provided.

    00000722
    58.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-75027 Themify Builder WordPress Plugin Authorization Bypass Affects Styling Data https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-75027

    Post summary

    A brief announcement of CVE‑2026‑75027 affecting the Themify Builder WordPress plugin, noting an authorization bypass that impacts styling data; only a link to vulnerability details is provided.

    00000127
    4.1K followersView on X

Explore more