WordPress Plugin Vulnerability Allows Unauthorized Style Modifications

WordPress Plugin Vulnerability Allows Unauthorized Style Modifications

First seen 24 Aug 2026, 10:46 UTC Ciberseguridadlatam 88% similarity 54.9

Article Content

Browse articles
ThreatCluster

A critical vulnerability (CVE-2026-75027) in the Themify Builder plugin for WordPress has been disclosed, allowing unauthorized users to alter the styles of private posts. This issue arises from a public nonce that bypasses security checks, exposing hundreds of thousands of sites to potential manipulation. The vulnerability affects sites using the Themify Builder plugin, which is widely installed. As of August 22, 2026, the CVE has been published, but there is no indication of active exploitation at this time. Site administrators are advised to review their installations and apply necessary updates once available.

Key Points: • CVE-2026-75027 allows unauthorized style modifications on WordPress sites. • The vulnerability affects the Themify Builder plugin, installed on hundreds of thousands of sites. • A public nonce is the root cause of the security bypass, exposing private content.

ThreatCluster AI How this analysis works

Timeline

2026-08-22
CVE-2026-75027 published
A vulnerability in Themify Builder was disclosed, allowing unauthorized style modifications on WordPress sites.
Ciberseguridadlatam
2026-08-24
Vulnerability reported in cybersecurity news
Ciberseguridadlatam reported on the critical vulnerability affecting WordPress users, urging site admins to take action.
Ciberseguridadlatam

Community

Browse all →

Tracked Entities in This Story