CVE-2026-75027

Themify Builder <= 7.8.0 - Missing Authorization to Unauthenticated Arbitrary Builder Data Modification via 'tb_update_old_data' AJAX Action

The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify the stored Themify Builder styling data (padding and margin properties) of arbitrary posts, including private and draft posts, by supplying an attacker-controlled post ID and JSON styling payload. The nonce required by the handler is automatically emitted to all frontend pages rendered by the builder via wp_localize_script, meaning any unauthenticated visitor can trivially retrieve a valid nonce from page source and satisfy the only access control in place.


We have discovered 1,755 live websites that are affected by CVE-2026-75027.

Run a Free Instant Scan




Affected Software

Product  Themify Builder
Category Wordpress Plugins
Vulnerable Domains1,755 live websites (100% of Themify Builder install base)
Vulnerable Versions
  • from 0 through 7.8
Vulnerable Versions Count89 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Aug 22, 2026
  • Updated - Aug 24, 2026

Credits

  • Wordfence PRISM (finder)

Website Distribution by Country

Number of websites using CVE-2026-75027
United States660 websites



Germany210 websites
France72 websites
GB63 websites
Netherlands59 websites
Canada56 websites
Japan54 websites
Italy43 websites
Poland41 websites
Denmark32 websites

Website Distribution by TLD

Number of websites using CVE-2026-75027
.com769 websites
.org141 websites
.de130 websites
.nl50 websites
.ca43 websites
.co.uk41 websites
.net37 websites
.pl36 websites
.fr33 websites
.ru27 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-75027

Top websites that are affected by CVE-2026-75027. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com Bahrain**,***
*************.online United States**,***
*******.se Sweden***,***
*********.com United States***,***
******************.com United States***,***
**********.org Germany***,***
************.com United States***,***
****.com United States***,***
**********.com GB***,***
****************.de Germany***,***
See full domain list

FAQ

CVE-2026-75027 is Missing Authorization in Themify Builder
A total of 1,755 websites have been identified as vulnerable to CVE-2026-75027, based on global website indexing conducted by WebTechSurvey.
The Themify Builder is affected by the CVE-2026-75027 vulnerability.
Themify Builder versions up to and including 7.8 are vulnerable to CVE-2026-75027.

References