Tag
Themify Builder versions 7.8.1 and earlier are vulnerable to Stored Cross-Site Scripting (XSS) via the css[fonts] parameter, allowing unauthenticated attackers to inject malicious scripts due to exposed nonces.