WordPress security by component
Elegant Themes Divi
Elegant Themes Divi (divi) is a WordPress theme with 11 published CVE records in this archive. The latest tracked vulnerability was published Sep 05, 2026; the highest published CVSS base score is 9.9.
Theme slug:
diviLatest vulnerability
CVE-2026-4361: Divi permits Contributor-level blind SSRF
Divi through 4.27.6 uses wp_remote_get() in et_pb_set_video_oembed_thumbnail_resolution() to fetch a Contributor-controlled image URL without blocking private or reserved destinations. The response body is not returned, but differences in the returned URL and request timing provide status and reachability oracles for internal targets.
| Safe version |
|
||
|---|---|---|---|
| Sep 05, 2026 |
CVE-2026-4361
Divi permits Contributor-level blind SSRF
Divi through 4.27.6 uses wp_remote_get() in et_pb_set_video_oembed_thumbnail_resolution() to fetch a Contributor-controlled image URL without blocking private or reserved destinations. The response body is not returned, but differences in the returned URL and request timing provide status and reachability oracles for internal targets.
|
See mitigation notes |
CVE5.0
NVDPending
|
| Sep 05, 2026 |
CVE-2026-3853
Divi permits Contributor-level DOM stored XSS through video sliders
Divi through 4.27.6 does not treat the et_pb_video_slider_item image_src attribute as a URL during save-time validation. Although the server escapes it into data-image, the carousel browser-decodes the value and concatenates it into new HTML through jQuery.after() without re-escaping. A Contributor can store script that executes when a visitor hovers over the carousel thumbnail.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Sep 03, 2026 |
CVE-2026-3852
Divi contributors can store script in Skype social links
Divi through 4.27.6 does not apply URL validation or attribute-context escaping to the Social Media Follow module's skype_url shortcode attribute. A Contributor or higher can break out of the generated href attribute and store script that executes when a visitor interacts with the affected social link.
|
4.27.7 |
CVE6.4
NVDPending
|
| Sep 02, 2026 |
CVE-2026-3850
Divi contributors can store JavaScript redirect payloads
Divi's contact-form shortcode handles redirect_url with attribute escaping instead of URL-scheme validation and omits it from the builder's URL-option sanitization. A Contributor can store a javascript: redirect that executes when a visitor successfully submits the affected form. The authoritative description says versions through 4.27.6 are affected, while its structured affected range ends at 4.27.5.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Sep 02, 2026 |
CVE-2026-3851
Divi legacy dynamic content permits Contributor-level stored cross-site scripting
Divi through 4.27.6 sanitizes only @ET-DC@ dynamic-content markers while its renderer also accepts a legacy JSON form that is converted after save-time filtering. A Contributor or higher can use that legacy form with post_meta_key and enable_html enabled so et_builder_filter_resolve_default_dynamic_content() emits raw post metadata, causing stored script to execute when the page is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Aug 16, 2026 |
CVE-2026-13712
Divi: A security weakness
Divi is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is 5.0 to < 5.9.0.
|
5.9.0 |
CVE5.4
NVDPending
|
| Jun 18, 2024 |
CVE-2024-5533
Divi: Cross-site scripting
Divi is affected by cross-site scripting. Exploitation requires an authenticated author account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Dec 23, 2023 |
CVE-2023-6744
Divi: Cross-site scripting
Divi is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Aug 08, 2023 |
CVE-2023-29099
Divi: Cross-site scripting
Divi is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Jan 01, 2021 |
CVE-2020-35945
Divi: A security weakness
Divi is affected by a security weakness. Exploitation requires an authenticated contributor account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE9.9
NVD8.8
|
| Feb 11, 2015 |
CVE-2015-1579
Elegant Themes Divi: Filesystem traversal
Elegant Themes Divi is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVEPending
NVD5.0
|