{"error":0,"message":null,"data":{"name":"Divi","theme":"divi","link":"https:\/\/www.elegantthemes.com\/gallery\/divi\/","latest":null,"closed":null,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"088c3a0fbd31cae7a8303f91ea5fd6cd4c3eaacb2e1889cdde04cb850f1fe697","name":"Divi [divi] >= 3.0 - <= 4.5.2","description":null,"operator":{"min_version":"3.0","min_operator":"ge","max_version":"4.5.2","max_operator":"le","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-35945","name":"CVE-2020-35945","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-35945","description":"[en] An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side.","date":"2021-01-01"},{"id":"3dc26e807d8c911f8600f038f8d308e06b9b6e37","name":"WordPress Divi premium theme <= 4.5.2 - Authenticated Arbitrary File Upload vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/theme\/divi\/vulnerability\/wordpress-divi-premium-theme-4-5-2-authenticated-arbitrary-file-upload-vulnerability","description":"Authenticated Arbitrary File Upload vulnerability discovered by WordFence in WordPress Divi premium theme (versions <= 4.5.2).","date":"2020-08-04"},{"id":"bc250084-9549-4996-a11c-2a082f4d3f68","name":"Elegant Themes (Divi 3.0 - 4.5.2, Extra 2.0 - 4.5.2, Divi Builder 2.0 - 4.5.2) - Authenticated Arbitrary File Upload","link":"https:\/\/wpscan.com\/vulnerability\/bc250084-9549-4996-a11c-2a082f4d3f68","description":"This flaw gave authenticated attackers, with contributor-level or above capabilities, the ability to upload arbitrary files, including PHP files, and achieve remote code execution on a vulnerable site&rsquo;s server.","date":null},{"id":"2b7a0d1d911573f1ea6441f9f898201f4f2cb24b","name":"Elegant Themes (Multiple Versions) - Arbitrary File Upload","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/elegant-themes-multiple-versions-arbitrary-file-upload","description":"An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side rather than server side.","date":"2020-08-03"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-434","name":"Unrestricted Upload of File with Dangerous Type","description":"The product allows the upload or transfer of dangerous file types that are automatically processed within its environment."}]}},{"uuid":"4ec7a4d6b42ee1c5bf3370a4fac212176ad1aa66aba0e88a42f56cf2dc25b455","name":"Divi [divi] < 4.0.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.0.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"5184e5a8a3f35b89ce959a25e0065a9fbf68d7f7","name":"WordPress Divi premium theme <= 4.0.9 - Authenticated Code Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/theme\/divi\/vulnerability\/wordpress-divi-premium-theme-4-0-9-authenticated-code-injection","description":"Authenticated Code Injection vulnerability found in WordPress Divi premium theme (versions <= 4.0.9).","date":"2020-01-05"}],"impact":[]},{"uuid":"3c640a902447b83d16ea6b908782b6a253083037ccf144d61b57ceaa1473d1fa","name":"Divi [divi] < 2.6.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.6.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"9299fce625c4c6100da5b303199a9caceb3be4cf","name":"WordPress  Elegant Themes <= 2.6.3 - Privilege Escalation","link":"https:\/\/patchstack.com\/database\/wordpress\/theme\/elegant\/vulnerability\/wordpress-elegant-themes-2-6-3-privilege-escalation","description":"WordPress Elegant Themes' products, such as Divi Builder, Divi, Extra and Divi 2.3, are prone to a privilege escalation vulnerability.\nUpdate the theme.","date":"2016-02-18"}],"impact":[]},{"uuid":"42046ffb6ed45613883337881b8d9c83a0369d559f272b8b2406e4a76bac4c7b","name":"Divi [divi] < 2.6.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.6.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"c253d387-f05a-4a68-9554-ecb846942b28","name":"wpscan.com","link":"https:\/\/wpscan.com\/vulnerability\/c253d387-f05a-4a68-9554-ecb846942b28","description":null,"date":null}],"impact":[]},{"uuid":"646642a6fc80900dcd254fb7fb7a6ddd66e66bb0448ddee5c02d4f8a55b97f67","name":"Divi [divi] >= 3.23 - <= 4.0.9","description":null,"operator":{"min_version":"3.23","min_operator":"ge","max_version":"4.0.9","max_operator":"le","unfixed":"0","closed":"0"},"source":[{"id":"a9a0356c37fc58c17c2529f1f0e2b6d2eb35635a","name":"Elegant Themes Divi 3.23 - 4.0.9, Divi Extra 2.23 - 4.0.9, Divi Builder 2.23 - 4.0.9 - PHP Code Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/elegant-themes-divi-323-409-divi-extra-223-409-divi-builder-223-409-php-code-injection","description":"The Divi Builder, Divi, and Divi Extra plugin and themes for WordPress are vulnerable to PHP Code Injection in versions up to 4.0.10. This allows authenticated attackers to execute code on a vulnerable site's server that could be used to completely take over the site.","date":"2020-01-04"}],"impact":[]},{"uuid":"2844be20d945da85becc1cbaac90537ee5c0100a6a46352ba591eae42c9808e9","name":"Divi [divi] < 3.17.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.17.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"646a6192eaad3f76db9f13504ca350f150c1520c","name":"Elegant Themes (Various Versions) - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/elegant-themes-various-versions-stored-cross-site-scripting","description":"The Elegant Themes Divi Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.17.2 in addition to the following themes: Divi <= 3.17.2 and Extra <= 2.17.2 due to insufficient input sanitization and output escaping in the post builder. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2018-10-30"}],"impact":[]},{"uuid":"b2decc6c575018afb2c1ecc74cc5ce0854708d909002f585db8133077c173ca4","name":"Divi [divi] < 4.20.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.20.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-29099","name":"CVE-2023-29099","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-29099","description":"[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Elegant themes Divi theme <=\u00a04.20.2 versions.","date":"2023-08-08"},{"id":"aec94cbe6f318bed983101c205e82e9eba241fc6","name":"WordPress  Divi Theme  <= 4.20.2 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/theme\/divi\/vulnerability\/wordpress-divi-theme-4-20-2-contributor-cross-site-scripting-xss-vulnerability","description":"Update the WordPress Divi theme to the latest available version (at least 4.20.3).\nRafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Divi Theme. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 4.20.3.","date":"2023-05-09"},{"id":"aa34a4b33b9ea29dfdfe46a5a9d4ddc5a7674a9b","name":"Divi <= 4.20.2 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Divi\/divi-4202-authenticated-contributor-stored-cross-site-scripting","description":"The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.20.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-05-09"},{"id":"f8b5a18e-b72f-4da0-94a8-3ae83d686d8a","name":"Divi &lt; 4.20.3 - Contributor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/f8b5a18e-b72f-4da0-94a8-3ae83d686d8a","description":"The theme does not validate and escape some parameters, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"6.5","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"e8cdfed5ffab7ad23e434f2e2b5abe798ec83d5b882cdd9bdd79b89cdf208ce5","name":"Divi [divi] < 4.23.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.23.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-6744","name":"CVE-2023-6744","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-6744","description":"[en] The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'et_pb_text' shortcode in all versions up to, and including, 4.23.1 due to insufficient input sanitization and output escaping on user supplied custom field data. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-12-23"},{"id":"bf35aa02f805b39d382ddcd92756513592808e0e","name":"Divi <= 4.23.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Divi\/divi-4231-authenticated-contributor-stored-cross-site-scripting-via-shortcode","description":"The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'et_pb_text' shortcode in all versions up to, and including, 4.23.1 due to insufficient input sanitization and output escaping on user supplied custom field data. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-12-22"},{"id":"6eb694630fa194a0bc1141b06a87cfd7ac810950","name":"WordPress  Divi Theme  <= 4.23.1 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/theme\/divi\/vulnerability\/wordpress-divi-plugin-4-23-1-auth-contributor-stored-cross-site-scripting-vulnerability","description":"Update the WordPress Divi Theme to the latest available version (at least 4.23.2).\nFrancesco Carlucci discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Divi Theme. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 4.23.2.\nHave additional information or questions about this entry? Get in touch.","date":"2024-12-27"},{"id":"4dfa19af-6aa2-4cf4-95bd-ac2d19d442ec","name":"Divi &lt; 4.23.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode","link":"https:\/\/wpscan.com\/vulnerability\/4dfa19af-6aa2-4cf4-95bd-ac2d19d442ec","description":"The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin&#039;s &#039;et_pb_text&#039; shortcode in all versions up to, and including, 4.23.1 due to insufficient input sanitization and output escaping on user supplied custom field data. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"fff842fdcbfe8dc820b93620edc5635d07ae0dd07ae8f297f7d27f34c1c14b4e","name":"Divi [divi] < 4.25.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.25.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-4490","name":"CVE-2024-4490","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-4490","description":"[en] The Elegant Themes Divi theme, Extra theme, and Divi Page Builder plugin for WordPress are vulnerable to DOM-Based Stored Cross-Site Scripting via the \u2018title\u2019 parameter in versions up to, and including, 4.25.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-10"},{"id":"9b764dab7bdb00c00c56b681beddce08e752f167","name":"Elegant Themes Divi Theme, Extra Theme, Divi Page Builder <= 4.25.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/elegant-themes-divi-theme-extra-theme-divi-page-builder-4250-authenticated-contributor-dom-based-stored-cross-site-scripting","description":"The Elegant Themes Divi theme, Extra theme, and Divi Page Builder plugin for WordPress are vulnerable to DOM-Based Stored Cross-Site Scripting via the \u2018title\u2019 parameter in versions up to, and including, 4.25.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-09"},{"id":"4939894c988bf7971824c37db3abd1c7e1107e23","name":"WordPress Divi Builder Plugin <= 4.25.0 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/divi-builder\/vulnerability\/wordpress-divi-builder-plugin-4-25-0-authenticated-contributor-dom-based-stored-cross-site-scripting-vulnerability","description":"<p>WordPress Divi Builder Plugin <= 4.25.0 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Affected Version <= 4.25.0<\/p><p>Fixed in version 4.25.1 <\/p>","date":"2024-05-10"},{"id":"6a0f7f4eeab0e9fa2ffb0eee652d2f9421540838","name":"WordPress Divi Theme <= 4.25.0 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/theme\/divi\/vulnerability\/wordpress-divi-theme-4-25-0-authenticated-contributor-dom-based-stored-cross-site-scripting-vulnerability","description":"<p>WordPress Divi Theme <= 4.25.0 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Affected Version <= 4.25.0<\/p><p>Fixed in version 4.25.1 <\/p>","date":"2024-05-10"},{"id":"4ef0f94a1e0813b569630516374fc066460f85ad","name":"WordPress Extra Theme <= 4.25.0 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/theme\/extra\/vulnerability\/wordpress-extra-theme-4-25-0-authenticated-contributor-dom-based-stored-cross-site-scripting-vulnerability","description":"<p>WordPress Extra Theme <= 4.25.0 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Affected Version <= 4.25.0<\/p><p>Fixed in version 4.25.1 <\/p>","date":"2024-05-10"},{"id":"4c3145cb-e208-4a8e-afce-56106a9b1d58","name":"Elegant Themes Divi Theme, Extra Theme, Divi Page Builder &lt;= 4.25.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/4c3145cb-e208-4a8e-afce-56106a9b1d58","description":"The Elegant Themes Divi theme, Extra theme, and Divi Page Builder plugin for WordPress are vulnerable to DOM-Based Stored Cross-Site Scripting via the &lsquo;title&rsquo; parameter in versions up to, and including, 4.25.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"26cde1904aaf0adaca8638fa60b163178a32156f8bbe8dd0d7bd1b8c92015613","name":"Divi [divi] < 4.25.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.25.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-5533","name":"CVE-2024-5533","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-5533","description":"[en] The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.25.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-06-18"},{"id":"b0af61374264b700feed791920ae276d5f68cce1","name":"Divi <= 4.25.1 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Divi\/divi-4251-authenticated-contributor-stored-cross-site-scripting","description":"The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.25.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-06-17"},{"id":"e67272f8319b63792a7a0788ae194d9c3a5e6e93","name":"WordPress Divi Theme <= 4.25.1 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/theme\/divi\/vulnerability\/wordpress-divi-theme-4-25-1-authenticated-contributor-stored-cross-site-scripting-vulnerability","description":"<p>WordPress Divi Theme <= 4.25.1 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Affected Version <= 4.25.1<\/p><p>Fixed in version 4.25.2 <\/p>","date":"2024-06-18"},{"id":"622a047d-8e9f-484f-bda1-0a91410c7788","name":"Divi &lt; 4.25.2 - Contributor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/622a047d-8e9f-484f-bda1-0a91410c7788","description":"The theme is vulnerable to Stored Cross-Site Scripting due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-20","name":"Improper Input Validation","description":"The product receives input or data, but it does\n        not validate or incorrectly validates that the input has the\n        properties that are required to process the data safely and\n        correctly."},{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"016f75b78f58a4dd8c218b2373d01b6fe159c7e18679a25ba96756a510bb5128","name":"Divi [divi] < 4.27.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.27.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8fdec6763b3c730130b642406e93234959989593","name":"Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/multiple-plugins-various-versions-authenticated-contributor-stored-dom-based-cross-site-scripting-via-magnific-popups-javascript-library","description":"Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was fixed in the upstream library (Magnific Popups version 1.2.0) by disabling the loading of HTML within certain fields by default.","date":"2025-07-02"},{"id":"CVE-2024-5647","name":"CVE-2024-5647","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-5647","description":"[en] Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was fixed in the upstream library (Magnific Popups version 1.2.0) by disabling the loading of HTML within certain fields by default.","date":"2025-07-03"},{"id":"c2998af6-d000-4da5-a60d-dbc6e52474bf","name":"Magnific Popups JavaScript Library &lt; 1.2.0 - Contributor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/c2998af6-d000-4da5-a60d-dbc6e52474bf","description":"Multiple plugins are vulnerable to Stored Cross-Site Scripting via the plugin&#039;s bundled Magnific Popups library (version 1.1.0) due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was fixed in the upstream library (Magnific Popups version 1.2.0) by disabling the loading of HTML within certain fields by default.","date":"2025-07-02"},{"id":"EUVD-2024-54725","name":"EUVD-2024-54725","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-54725","description":"Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was fixed in the upstream library (Magnific Popups version 1.2.0) by disabling the loading of HTML within certain fields by default.","date":"2025-07-03"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"062df1fc4800fc2e8c1c0f9b0b02fb880220ddb23aa2852ba594c47e11f322fe","name":"Divi [divi] >= 5.0 - < 5.9.0","description":null,"operator":{"min_version":"5.0","min_operator":"ge","max_version":"5.9.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-13712","name":"CVE-2026-13712","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-13712","description":"[en] The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow module settings before outputting them in link attributes, allowing users with a role as low as contributor to store JavaScript which will run when a higher privileged user, such as an administrator, views the post.","date":"2026-08-16"},{"id":"1b687d33658af825baa7a981238a7016ea9f9a72","name":"Divi <= 5.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Divi\/divi-581-authenticated-contributor-stored-cross-site-scripting","description":"The Divi plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.8.1. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-07-02"}],"impact":{"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"4b34475030e5ca2f0657930fe1db20bdefe4522d6d6d0a8e56c5d6cc01d769e8","name":"Divi [divi] < 4.27.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.27.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-3851","name":"CVE-2026-3851","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-3851","description":"[en] The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Dynamic Content feature's legacy JSON format in all versions up to, and including, 4.27.6. This is due to two compounding flaws: (1) the save-time sanitization filter `et_builder_sanitize_dynamic_content_fields()` only searches for dynamic content markers in the `@ET-DC@...@` format, but the rendering engine also supports a legacy JSON format that is silently converted at render time, completely bypassing the save-time filter, and (2) the `post_meta_key` resolver in `et_builder_filter_resolve_default_dynamic_content()` does not apply `wp_kses_post()` to the resolved meta value when `enable_html` is set to `on`, passing raw `get_post_meta()` output directly to the page. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-09-02"},{"id":"f203f192f76f3351d94d9cfdae83b8f2399ef093","name":"WordPress Divi Theme <= 4.27.6 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/theme\/divi\/vulnerability\/wordpress-divi-plugin-4-27-6-authenticated-contributor-stored-cross-site-scripting-via-dynamic-content-legacy-json-format-shortcode-vulnerability","description":"<p>WordPress Divi Theme <= 4.27.6 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Divi<\/p><p>Fixed in version 4.27.7 <\/p><p>Affected Version <= 4.27.6<\/p><p>CVE: CVE-2026-3851<\/p>","date":"2026-09-01"},{"id":"fe532031de22b8a35b28737e0ca25f53797cc8ce","name":"Divi <= 4.27.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Dynamic Content (Legacy JSON Format) Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Divi\/divi-4276-authenticated-contributor-stored-cross-site-scripting-via-dynamic-content-legacy-json-format-shortcode","description":"The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Dynamic Content feature's legacy JSON format in all versions up to, and including, 4.27.6. This is due to two compounding flaws: (1) the save-time sanitization filter `et_builder_sanitize_dynamic_content_fields()` only searches for dynamic content markers in the `@ET-DC@...@` format, but the rendering engine also supports a legacy JSON format that is silently converted at render time, completely bypassing the save-time filter, and (2) the `post_meta_key` resolver in `et_builder_filter_resolve_default_dynamic_content()` does not apply `wp_kses_post()` to the resolved meta value when `enable_html` is set to `on`, passing raw `get_post_meta()` output directly to the page. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-09-01"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"676399f8535092fb4807b4c928be41fa464acca709a2861fece5b2cf3eb6c696","name":"Divi [divi] < 4.27.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.27.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-3850","name":"CVE-2026-3850","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-3850","description":"[en] The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `redirect_url` parameter of the `et_pb_contact_form` shortcode in all versions up to, and including, 4.27.6. This is due to the `redirect_url` attribute being sanitized with `esc_attr()` instead of `esc_url()` before being rendered into the `data-redirect_url` HTML data attribute. Additionally, `redirect_url` is absent from the hardcoded `$url_options` array in `class-et-builder-element.php`, so it does not receive `esc_url_raw()` sanitization during shortcode parsing. After a successful form submission, client-side JavaScript reads this data attribute and passes it directly to `window.location.href`, executing arbitrary JavaScript from a `javascript:` URI. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that execute whenever a user submits the contact form.","date":"2026-09-02"},{"id":"9d4753ad23194fe9522ce493716aacf923008449","name":"Divi <= 4.27.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Contact Form 'redirect_url' Shortcode Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Divi\/divi-4276-authenticated-contributor-stored-cross-site-scripting-via-contact-form-redirect-url-shortcode-parameter","description":"The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `redirect_url` parameter of the `et_pb_contact_form` shortcode in all versions up to, and including, 4.27.6. This is due to the `redirect_url` attribute being sanitized with `esc_attr()` instead of `esc_url()` before being rendered into the `data-redirect_url` HTML data attribute. Additionally, `redirect_url` is absent from the hardcoded `$url_options` array in `class-et-builder-element.php`, so it does not receive `esc_url_raw()` sanitization during shortcode parsing. After a successful form submission, client-side JavaScript reads this data attribute and passes it directly to `window.location.href`, executing arbitrary JavaScript from a `javascript:` URI. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that execute whenever a user submits the contact form.","date":"2026-09-01"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"0c0bb2529ab5bcb69dc69dcd4731733e59b9cc8ad99cf0f9193c15709972fa33","name":"Divi [divi] < 4.27.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.27.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-3852","name":"CVE-2026-3852","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-3852","description":"[en] The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `skype_url` shortcode attribute of the Social Media Follow module in all versions up to, and including, 4.27.6. This is due to a three-part sanitization failure: (1) the `skype_url` field is not included in the `$url_options` whitelist in `class-et-builder-element.php`, so it never invokes `esc_url_raw()` during shortcode processing, (2) the render code in `SocialMediaFollowItem.php` explicitly skips `esc_url()` for Skype URLs (`! $is_skype ? esc_url( $url ) : $skype_url`), and (3) only `sanitize_text_field()` is applied, which preserves single and double quote characters allowing attribute breakout. The unsanitized value is interpolated directly into a single-quoted `href` attribute (`href='{$social_network_link_url}'`). This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user interacts with the injected element.","date":"2026-09-03"},{"id":"5c9e77e1e21dbd0087745ef8b67deab492f3e28a","name":"Divi <= 4.27.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Social Media Follow 'skype_url' Shortcode Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Divi\/divi-4276-authenticated-contributor-stored-cross-site-scripting-via-social-media-follow-skype-url-shortcode-parameter","description":"The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `skype_url` shortcode attribute of the Social Media Follow module in all versions up to, and including, 4.27.6. This is due to a three-part sanitization failure: (1) the `skype_url` field is not included in the `$url_options` whitelist in `class-et-builder-element.php`, so it never invokes `esc_url_raw()` during shortcode processing, (2) the render code in `SocialMediaFollowItem.php` explicitly skips `esc_url()` for Skype URLs (`! $is_skype ? esc_url( $url ) : $skype_url`), and (3) only `sanitize_text_field()` is applied, which preserves single and double quote characters allowing attribute breakout. The unsanitized value is interpolated directly into a single-quoted `href` attribute (`href='{$social_network_link_url}'`). This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user interacts with the injected element.","date":"2026-09-01"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"997ec88f54c92d50e634bc5bfc1d08939b52f6434490e58e3ef283fa9246dac4","name":"Divi [divi] < 4.27.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.27.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-4361","name":"CVE-2026-4361","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-4361","description":"","date":"0000-00-00"},{"id":"c1acb150aab6f61c9f83431c2f97572bcf8c89c0","name":"Divi <= 4.27.6 - Authenticated (Contributor+) Server-Side Request Forgery via 'image_src' Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Divi\/divi-4276-authenticated-contributor-server-side-request-forgery-via-image-src-parameter","description":"The Divi theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.27.6. This is due to the `et_pb_set_video_oembed_thumbnail_resolution()` function using `wp_remote_get()` instead of `wp_safe_remote_get()` to fetch a remote image URL, which does not restrict requests to private or reserved IP ranges. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application server. The response body is not returned to the attacker (blind SSRF), but two oracles exist: a status oracle (the returned URL string differs depending on whether the target responded with HTTP 200) and a timing oracle (response time varies by target reachability).","date":"2026-09-04"}],"impact":[]},{"uuid":"f97ed60354c1fed98bc99655d750692c28f83fd873d1d1a118c8a30cd91e21c1","name":"Divi [divi] < 4.27.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.27.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-3853","name":"CVE-2026-3853","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-3853","description":"","date":"0000-00-00"},{"id":"7fcdf21fb3acbd1f1bc6bf9a087988199a0e9036","name":"Divi <= 4.27.6 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Video Slider 'image_src' Shortcode Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-themes\/Divi\/divi-4276-authenticated-contributor-dom-based-stored-cross-site-scripting-via-video-slider-image-src-shortcode-parameter","description":"The Divi theme for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the `image_src` attribute of the `et_pb_video_slider_item` shortcode in all versions up to, and including, 4.27.6. This is due to the `image_src` field not being included in the `$url_options` whitelist (which only contains `url`, `button_link`, `button_url`), so it never receives `esc_url_raw()` at save time. On the server side, the value is rendered into a `data-image` HTML attribute using `esc_attr()`, which encodes double quotes as `\"`. However, the client-side JavaScript carousel code in `custom.unified.js` reads this attribute using jQuery's `.data('image')`, which returns the browser-decoded value (with `\"` decoded back to `\"`). The decoded value is then concatenated directly into an HTML string and injected into the DOM via `jQuery.after()` without re-escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user hovers over the carousel thumbnail.","date":"2026-09-04"}],"impact":[]}]},"updated":"1788601872"}