{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/themify/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:themify:builder:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-95864"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Themify Builder (\u003c= 7.8.1)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","xss","wordpress","cve-2026-95864"],"_cs_type":"advisory","_cs_vendors":["Themify"],"content_html":"\u003cp\u003eThemify Builder, a popular WordPress plugin, contains a Stored Cross-Site Scripting (XSS) vulnerability in versions 7.8.1 and earlier, tracked as CVE-2026-95864. The flaw exists within the 'css[fonts]' parameter, which fails to adequately sanitize user-supplied input or escape output.\u003c/p\u003e\n\u003cp\u003eThe security impact is compounded by the fact that the required nonce is embedded within the site's front-end markup, accessible to any visitor. This effectively bypasses standard authentication requirements, allowing unauthenticated remote attackers to inject arbitrary web scripts into pages. When an authorized user or administrator accesses a compromised page, the injected script executes within the context of their session. This can lead to session hijacking, unauthorized administrative actions, or the redirection of users to malicious infrastructure. Defenders should prioritize updating the plugin to a patched version once available and monitor web server access logs for anomalous POST requests directed at plugin-related endpoints.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the browser of any user viewing the injected content. This could result in unauthorized administrative actions, sensitive information disclosure via session theft, or the compromise of user accounts. The vulnerability affects all WordPress instances running Themify Builder 7.8.1 and earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor web server logs for suspicious POST requests containing unusual patterns in the 'css[fonts]' parameter.\u003c/li\u003e\n\u003cli\u003eImplement a Content Security Policy (CSP) to mitigate the impact of XSS by restricting the sources from which scripts can be executed.\u003c/li\u003e\n\u003cli\u003eUpgrade Themify Builder to the latest version immediately upon the release of a security patch by the vendor.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-25T08:58:56Z","date_published":"2026-09-25T08:58:56Z","id":"https://feed.craftedsignal.io/briefs/2026-09-themify-builder-xss/","summary":"Themify Builder versions 7.8.1 and earlier are vulnerable to Stored Cross-Site Scripting (XSS) via the css[fonts] parameter, allowing unauthenticated attackers to inject malicious scripts due to exposed nonces.","title":"Stored XSS in Themify Builder via css[fonts] Parameter","url":"https://feed.craftedsignal.io/briefs/2026-09-themify-builder-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Themify","version":"https://jsonfeed.org/version/1.1"}