The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Map Module 'b_width_map' Field in all versions up to, and including, 7.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 1,766 live websites that are affected by CVE-2026-15096.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 1,766 live websites (100% of Themify Builder install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 87 versions ( 100% of all versions) |
| 667 websites | |
| 210 websites | |
| 73 websites | |
| 64 websites | |
| 57 websites | |
| 56 websites | |
| 54 websites | |
| 44 websites | |
| 40 websites | |
| 32 websites |
| .com | 776 websites |
| .org | 144 websites |
| .de | 130 websites |
| .nl | 47 websites |
| .ca | 43 websites |
| .co.uk | 42 websites |
| .net | 36 websites |
| .pl | 35 websites |
| .fr | 33 websites |
| .it | 27 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.com | **,*** | ||
| *************.online | **,*** | ||
| *******.se | ***,*** | ||
| *********.com | ***,*** | ||
| ******************.com | ***,*** | ||
| **********.org | ***,*** | ||
| ************.com | ***,*** | ||
| ****.com | ***,*** | ||
| **********.com | ***,*** | ||
| ****************.de | ***,*** |
FAQ