CVE-2024-5647
- EPSS 0.07%
- Veröffentlicht 03.07.2025 09:22:19
- Zuletzt bearbeitet 03.07.2025 15:13:53
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. ...
CVE-2024-5533
- EPSS 0.2%
- Veröffentlicht 18.06.2024 08:15:50
- Zuletzt bearbeitet 21.11.2024 09:47:52
The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.25.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level a...
CVE-2024-4490
- EPSS 0.24%
- Veröffentlicht 14.05.2024 15:43:53
- Zuletzt bearbeitet 21.11.2024 09:42:55
The Elegant Themes Divi theme, Extra theme, and Divi Page Builder plugin for WordPress are vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘title’ parameter in versions up to, and including, 4.25.0 due to insufficient input sanitization a...
CVE-2023-6744
- EPSS 0.18%
- Veröffentlicht 23.12.2023 10:15:10
- Zuletzt bearbeitet 21.11.2024 08:44:28
The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'et_pb_text' shortcode in all versions up to, and including, 4.23.1 due to insufficient input sanitization and output escaping on user supplied custom field da...
CVE-2023-29099
- EPSS 0.08%
- Veröffentlicht 08.08.2023 11:15:10
- Zuletzt bearbeitet 28.01.2026 20:39:35
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Elegant themes Divi theme <= 4.20.2 versions.
CVE-2020-35945
- EPSS 2.23%
- Veröffentlicht 01.01.2021 04:15:13
- Zuletzt bearbeitet 04.02.2026 18:54:43
An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs beca...
- EPSS 80.82%
- Veröffentlicht 11.02.2015 19:59:06
- Zuletzt bearbeitet 28.01.2026 20:39:35
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image action to wp-admin/admin-ajax.php. NOTE: this vulnerab...