Impact
The Themify Builder plugin allows a stored cross‑site scripting flaw because the value supplied to the css[fonts] parameter is not sanitized or escaped before being written to the database. An attacker can inject JavaScript that will execute in the browser whenever a user views a page containing the injected content. The injected script runs in the context of the site, giving the attacker the ability to steal cookies, hijack sessions, deface the site, or spread malware to visitors. The flaw is not a privilege escalation; anyone can inject the payload once the vulnerable endpoint is reached.
Affected Systems
WordPress sites that have the Themify Builder plugin installed, specifically any release up to and including version 7.8.1. The plugin is offered by themifyme as Themify Builder.
Risk and Exploitability
The CVSS score of 7.2 marks the vulnerability with high severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog. The attack vector is inferred to be unauthenticated because the necessary nonce is embedded in the page markup and exposed to all visitors, effectively removing authentication barriers. Once a payload is stored, every subsequent visitor executing the page will run the injected code, which can result in widespread compromise of users and the site itself.
OpenCVE Enrichment