Ciberseguridadlatam
WordPress Plugin Vulnerability Allows Unauthorized Style Modifications
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Article Content
A critical vulnerability (CVE-2026-75027) in the Themify Builder plugin for WordPress has been disclosed, allowing unauthorized users to alter the styles of private posts. This issue arises from a public nonce that bypasses security checks, exposing hundreds of thousands of sites to potential manipulation. The vulnerability affects sites using the Themify Builder plugin, which is widely installed. As of August 22, 2026, the CVE has been published, but there is no indication of active exploitation at this time. Site administrators are advised to review their installations and apply necessary updates once available.
Key Points: • CVE-2026-75027 allows unauthorized style modifications on WordPress sites. • The vulnerability affects the Themify Builder plugin, installed on hundreds of thousands of sites. • A public nonce is the root cause of the security bypass, exposing private content.