← WordPress Vulnerabilities
WordPress security by component

Elegant Themes Divi

Elegant Themes Divi (divi) is a WordPress theme with 11 published CVE records in this archive. The latest tracked vulnerability was published Sep 05, 2026; the highest published CVSS base score is 9.9.

Theme slug: divi

CVE-2026-4361: Divi permits Contributor-level blind SSRF

Divi through 4.27.6 uses wp_remote_get() in et_pb_set_video_oembed_thumbnail_resolution() to fetch a Contributor-controlled image URL without blocking private or reserved destinations. The response body is not returned, but differences in the returned URL and request timing provide status and reachability oracles for internal targets.

PublishedSep 05, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for divi
Safe version
Sep 05, 2026 CVE-2026-4361
Divi permits Contributor-level blind SSRF
Divi through 4.27.6 uses wp_remote_get() in et_pb_set_video_oembed_thumbnail_resolution() to fetch a Contributor-controlled image URL without blocking private or reserved destinations. The response body is not returned, but differences in the returned URL and request timing provide status and reachability oracles for internal targets.
See mitigation notes
CVE5.0
NVDPending
Sep 05, 2026 CVE-2026-3853
Divi permits Contributor-level DOM stored XSS through video sliders
Divi through 4.27.6 does not treat the et_pb_video_slider_item image_src attribute as a URL during save-time validation. Although the server escapes it into data-image, the carousel browser-decodes the value and concatenates it into new HTML through jQuery.after() without re-escaping. A Contributor can store script that executes when a visitor hovers over the carousel thumbnail.
See mitigation notes
CVE6.4
NVDPending
Sep 03, 2026 CVE-2026-3852
Divi contributors can store script in Skype social links
Divi through 4.27.6 does not apply URL validation or attribute-context escaping to the Social Media Follow module's skype_url shortcode attribute. A Contributor or higher can break out of the generated href attribute and store script that executes when a visitor interacts with the affected social link.
4.27.7
CVE6.4
NVDPending
Sep 02, 2026 CVE-2026-3850
Divi contributors can store JavaScript redirect payloads
Divi's contact-form shortcode handles redirect_url with attribute escaping instead of URL-scheme validation and omits it from the builder's URL-option sanitization. A Contributor can store a javascript: redirect that executes when a visitor successfully submits the affected form. The authoritative description says versions through 4.27.6 are affected, while its structured affected range ends at 4.27.5.
See mitigation notes
CVE6.4
NVDPending
Sep 02, 2026 CVE-2026-3851
Divi legacy dynamic content permits Contributor-level stored cross-site scripting
Divi through 4.27.6 sanitizes only @ET-DC@ dynamic-content markers while its renderer also accepts a legacy JSON form that is converted after save-time filtering. A Contributor or higher can use that legacy form with post_meta_key and enable_html enabled so et_builder_filter_resolve_default_dynamic_content() emits raw post metadata, causing stored script to execute when the page is viewed.
See mitigation notes
CVE6.4
NVDPending
Aug 16, 2026 CVE-2026-13712
Divi: A security weakness
Divi is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is 5.0 to < 5.9.0.
5.9.0
CVE5.4
NVDPending
Jun 18, 2024 CVE-2024-5533
Divi: Cross-site scripting
Divi is affected by cross-site scripting. Exploitation requires an authenticated author account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Dec 23, 2023 CVE-2023-6744
Divi: Cross-site scripting
Divi is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Aug 08, 2023 CVE-2023-29099
Divi: Cross-site scripting
Divi is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Jan 01, 2021 CVE-2020-35945
Divi: A security weakness
Divi is affected by a security weakness. Exploitation requires an authenticated contributor account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.9
NVD8.8
Feb 11, 2015 CVE-2015-1579
Elegant Themes Divi: Filesystem traversal
Elegant Themes Divi is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVEPending
NVD5.0