CVE-2026-15096

Themify Builder <= 7.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Map Module 'b_width_map' Field

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Map Module 'b_width_map' Field in all versions up to, and including, 7.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 1,766 live websites that are affected by CVE-2026-15096.

Run a Free Instant Scan




Affected Software

Product  Themify Builder
Category Wordpress Plugins
Vulnerable Domains1,766 live websites (100% of Themify Builder install base)
Vulnerable Versions
  • from 0 through 7.7.6
Vulnerable Versions Count87 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 11, 2026
  • Updated - Jul 13, 2026

Credits

  • PRISM (finder)

Website Distribution by Country

Number of websites using CVE-2026-15096
United States667 websites



Germany210 websites
France73 websites
GB64 websites
Netherlands57 websites
Canada56 websites
Japan54 websites
Italy44 websites
Poland40 websites
Denmark32 websites

Website Distribution by TLD

Number of websites using CVE-2026-15096
.com776 websites
.org144 websites
.de130 websites
.nl47 websites
.ca43 websites
.co.uk42 websites
.net36 websites
.pl35 websites
.fr33 websites
.it27 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-15096

Top websites that are affected by CVE-2026-15096. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com Bahrain**,***
*************.online United States**,***
*******.se Sweden***,***
*********.com United States***,***
******************.com United States***,***
**********.org Germany***,***
************.com United States***,***
****.com United States***,***
**********.com GB***,***
****************.de Germany***,***
See full domain list

FAQ

CVE-2026-15096 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Themify Builder
A total of 1,766 websites have been identified as vulnerable to CVE-2026-15096, based on global website indexing conducted by WebTechSurvey.
The Themify Builder is affected by the CVE-2026-15096 vulnerability.
Themify Builder versions up to and including 7.7.6 are vulnerable to CVE-2026-15096.