Themify Builder
BitFire FREE Bot Protection and WAF stop the unauthenticated AJAX request behind CVE-2026-95864 before it stores script on your site.
- Affected sites
- 5,000+
- Attack class
- Stored Cross-site Scripting
Review the attack behind each advisory and the BitFire control—bot protection, WAF, or runtime RASP—that prevents it from becoming a compromise.
Showing 13–18 of 44 records · Updated September 29, 2026
BitFire FREE Bot Protection and WAF stop the unauthenticated AJAX request behind CVE-2026-95864 before it stores script on your site.
BitFire's WAF blocks the wpForo CVE-2026-93747 stored XSS payload at the request layer, before it is stored or ever rendered to an admin.
BitFire's FREE WAF blocks CVE-2026-93656's payload-bearing request before Profile Builder can persist it or an administrator's browser can run it.
BitFire's WAF detects and blocks the unauthenticated stored DOM-based XSS payload in HT Contact Form ≤ 2.10.1 before WordPress processes the request.
BitFire FREE blocks the double-encoded traversal before vulnerable WordPress template resolution can include an attacker-selected PHP file.
BitFire FREE blocks the double-encoded traversal local file inclusion before vulnerable WordPress template resolution can include an attacker-selected PHP file.
Page 3 of 8
BitFire combines bot controls, request inspection, and runtime enforcement so emerging vulnerabilities fail before a CVE-specific rule exists.