Elegantthemes

Divi

13 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 18.09.2026 06:38:53
  • Zuletzt bearbeitet 18.09.2026 15:17:18

The The Divi theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.11.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_sh...

  • EPSS 0.28%
  • Veröffentlicht 05.09.2026 06:37:59
  • Zuletzt bearbeitet 08.09.2026 13:12:58

The Divi theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.27.6. This is due to the `et_pb_set_video_oembed_thumbnail_resolution()` function using `wp_remote_get()` instead of `wp_safe_remote_get...

  • EPSS 0.17%
  • Veröffentlicht 05.09.2026 06:37:58
  • Zuletzt bearbeitet 08.09.2026 13:12:58

The Divi theme for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the `image_src` attribute of the `et_pb_video_slider_item` shortcode in all versions up to, and including, 4.27.6. This is due to the `image_src` field not being ...

  • EPSS 0.25%
  • Veröffentlicht 03.09.2026 08:28:09
  • Zuletzt bearbeitet 03.09.2026 17:25:25

The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `skype_url` shortcode attribute of the Social Media Follow module in all versions up to, and including, 4.27.6. This is due to a three-part sanitization failure: (1) th...

  • EPSS 0.16%
  • Veröffentlicht 02.09.2026 06:37:34
  • Zuletzt bearbeitet 04.09.2026 03:17:41

The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `redirect_url` parameter of the `et_pb_contact_form` shortcode in all versions up to, and including, 4.27.6. This is due to the `redirect_url` attribute being sanitized...

  • EPSS 0.17%
  • Veröffentlicht 02.09.2026 03:38:32
  • Zuletzt bearbeitet 03.09.2026 19:17:27

The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Dynamic Content feature's legacy JSON format in all versions up to, and including, 4.27.6. This is due to two compounding flaws: (1) the save-time sanitization filter `...

  • EPSS 0.3%
  • Veröffentlicht 03.07.2025 09:22:19
  • Zuletzt bearbeitet 25.08.2026 20:16:49

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. ...

  • EPSS 0.26%
  • Veröffentlicht 18.06.2024 08:15:50
  • Zuletzt bearbeitet 08.04.2026 18:22:05

The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.25.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level a...

  • EPSS 0.51%
  • Veröffentlicht 14.05.2024 15:43:53
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The Elegant Themes Divi theme, Extra theme, and Divi Page Builder plugin for WordPress are vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘title’ parameter in versions up to, and including, 4.25.0 due to insufficient input sanitization a...

  • EPSS 0.33%
  • Veröffentlicht 23.12.2023 10:15:10
  • Zuletzt bearbeitet 08.04.2026 18:18:41

The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'et_pb_text' shortcode in all versions up to, and including, 4.23.1 due to insufficient input sanitization and output escaping on user supplied custom field da...