Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library
medium
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-l...
- CVSS:
- 6.4
- Affected:
- up to 4.27.1
- Fixed in:
- 4.27.2
- Disclosed:
- Jul 2, 2025
CVE-2024-5647 on NVD →
Divi Builder [divi-builder] < 4.25.1
unknown
[en] The Elegant Themes Divi theme, Extra theme, and Divi Page Builder plugin for WordPress are vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘title’ parameter in versions up to, and including, 4.25.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated atta...
- Affected:
- up to 4.25.1
- Fixed in:
- 4.25.1
- Disclosed:
- May 10, 2024
CVE-2024-4490 on NVD →
Elegant Themes Divi Theme, Extra Theme, Divi Page Builder <= 4.25.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
medium
The Elegant Themes Divi theme, Extra theme, and Divi Page Builder plugin for WordPress are vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘title’ parameter in versions up to, and including, 4.25.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...
- CVSS:
- 6.4
- Affected:
- up to 4.25.0
- Fixed in:
- 4.25.1
- Disclosed:
- May 9, 2024
CVE-2024-4490 on NVD →
Divi Builder [divi-builder] >= 2.0 - <= 4.5.2
unknown
[en] An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side.
- Affected:
- 2.0 – 4.5.2
- Fixed in:
- 4.5.2
- Disclosed:
- Jan 1, 2021
CVE-2020-35945 on NVD →
Elegant Themes (Multiple Versions) - Arbitrary File Upload
high
An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side rather than se...
- CVSS:
- 8.8
- Affected:
- up to 4.3.2
- Fixed in:
- 4.5.3
- Disclosed:
- Aug 3, 2020
CVE-2020-35945 on NVD →
Divi Builder [divi-builder] < 4.0.10
unknown
Authenticated Code Injection vulnerability found in WordPress Divi Builder plugin (versions <= 4.0.9).
- Affected:
- up to 4.0.10
- Fixed in:
- 4.0.10
- Disclosed:
- Jan 5, 2020
Elegant Themes Divi 3.23 - 4.0.9, Divi Extra 2.23 - 4.0.9, Divi Builder 2.23 - 4.0.9 - PHP Code Injection
high
The Divi Builder, Divi, and Divi Extra plugin and themes for WordPress are vulnerable to PHP Code Injection in versions up to 4.0.10. This allows authenticated attackers to execute code on a vulnerable site's server that could be used to completely take over the site.
- CVSS:
- 8.8
- Affected:
- 2.23 – 4.0.9
- Fixed in:
- 4.0.10
- Disclosed:
- Jan 4, 2020
Divi Builder [divi-builder] >= 2.23 - <= 4.0.9
unknown
The Divi Builder, Divi, and Divi Extra plugin and themes for WordPress are vulnerable to PHP Code Injection in versions up to 4.0.10. This allows authenticated attackers to execute code on a vulnerable site's server that could be used to completely take over the site.
- Affected:
- 2.23 – 4.0.9
- Fixed in:
- 4.0.9
- Disclosed:
- Jan 4, 2020
Elegant Themes (Various Versions) - Stored Cross-Site Scripting
medium
The Elegant Themes Divi Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.17.2 in addition to the following themes: Divi <= 3.17.2 and Extra <= 2.17.2 due to insufficient input sanitization and output escaping in the post builder. This makes it possible for au...
- CVSS:
- 6.4
- Affected:
- up to 2.17.2
- Fixed in:
- 2.17.3
- Disclosed:
- Oct 30, 2018
Divi Builder [divi-builder] < 2.17.3
unknown
The Elegant Themes Divi Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.17.2 in addition to the following themes: Divi <= 3.17.2 and Extra <= 2.17.2 due to insufficient input sanitization and output escaping in the post builder. This makes it possible for au...
- Affected:
- up to 2.17.3
- Fixed in:
- 2.17.3
- Disclosed:
- Oct 30, 2018
Divi Builder [divi-builder] < 1.2.4
unknown
WordPress Elegant Themes' products, such as Divi Builder, Divi, Extra and Divi 2.3, are prone to a privilege escalation vulnerability.
Update the theme.
- Affected:
- up to 1.2.4
- Fixed in:
- 1.2.4
- Disclosed:
- Feb 18, 2016
Elegant Themes Monarch < 1.2.7 - Privilege Escalation
high
The Elegant Themes Monarch plugin before 1.2.7 for WordPress has privilege escalation.
- CVSS:
- 8.8
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.4
- Disclosed:
- Feb 17, 2016
CVE-2016-11004 on NVD →
Divi Builder [divi-builder] < 1.2.4
unknown
- Affected:
- up to 1.2.4
- Fixed in:
- 1.2.4
Divi Builder [divi-builder] < 4.0.10
unknown
"A code injection vulnerability was discovered by our team during a routine code audit that could allow logged in contributors, authors and editors to execute a small set of PHP functions."
Affected:
Divi version 3.23 and above,
Extra 2.23 and above
Divi Builder version 2.23 and above.
Product versio...
- Affected:
- up to 4.0.10
- Fixed in:
- 4.0.10
Divi Builder [divi-builder] < 2.17.3
unknown
A privilege escalation vulnerability was discovered that could allow low level users, such as Authors, to use unfiltered HTML inside of post content when using the Divi Builder. Using such code in posts is typically reserved for admins.
- Affected:
- up to 2.17.3
- Fixed in:
- 2.17.3
Divi Builder [divi-builder] < 4.27.2
unknown
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contribu...
- Affected:
- up to 4.27.2
- Fixed in:
- 4.27.2
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database