Impact
The Themify Builder plugin for WordPress contains an unchecked 'height_slider' Slider Module Field that allows authenticated users with contributor or higher privileges to store arbitrary JavaScript. Because the input is not sanitized or properly escaped, the malicious code is persisted to the database and then rendered in the front‑end when any visitor accesses a page containing the affected slider. The stored XSS payload can run in the user’s browser context, enablingacking, or phishing. This flaw is identified as CWE‑79.
Affected Systems
Any WordPress installation running Themify Builder version 7.7.6 or earlier is affected. The vulnerability is active only on sites where the attacker can create or edit sliders, i.e., users with contributor permissions or higher. If a site uses an older plugin, the flaw remains in place until the plugin is upgraded or existing sliders are removed.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, but the EPSS score of less than 1% suggests that large‑scale exploitation is currently unlikely. Because the flaw requires authenticated access, attackers must already have site privileges to inject scripts; however, once an injection is made, every visitor that loads the compromised page becomes a victim. The vulnerability is not listed in the CISA KEV catalog, but its impact could be wide if slider.
OpenCVE Enrichment