plugin

Divi Builder Vulnerabilities

16 known security issues reported for the Divi Builder WordPress plugin. Most recent disclosed Jul 2, 2025.

3 high 3 medium

Running Divi Builder on your site? Check whether your installed version is affected.

Scan your site free

Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library

medium

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-l...

CVSS:
6.4
Affected:
up to 4.27.1
Fixed in:
4.27.2
Disclosed:
Jul 2, 2025

CVE-2024-5647 on NVD →

Divi Builder [divi-builder] < 4.25.1

unknown

[en] The Elegant Themes Divi theme, Extra theme, and Divi Page Builder plugin for WordPress are vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘title’ parameter in versions up to, and including, 4.25.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated atta...

Affected:
up to 4.25.1
Fixed in:
4.25.1
Disclosed:
May 10, 2024

CVE-2024-4490 on NVD →

Elegant Themes Divi Theme, Extra Theme, Divi Page Builder <= 4.25.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

medium

The Elegant Themes Divi theme, Extra theme, and Divi Page Builder plugin for WordPress are vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘title’ parameter in versions up to, and including, 4.25.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...

CVSS:
6.4
Affected:
up to 4.25.0
Fixed in:
4.25.1
Disclosed:
May 9, 2024

CVE-2024-4490 on NVD →

Divi Builder [divi-builder] >= 2.0 - <= 4.5.2

unknown

[en] An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side.

Affected:
2.0 – 4.5.2
Fixed in:
4.5.2
Disclosed:
Jan 1, 2021

CVE-2020-35945 on NVD →

Elegant Themes (Multiple Versions) - Arbitrary File Upload

high

An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side rather than se...

CVSS:
8.8
Affected:
up to 4.3.2
Fixed in:
4.5.3
Disclosed:
Aug 3, 2020

CVE-2020-35945 on NVD →

Divi Builder [divi-builder] < 4.0.10

unknown

Authenticated Code Injection vulnerability found in WordPress Divi Builder plugin (versions <= 4.0.9).

Affected:
up to 4.0.10
Fixed in:
4.0.10
Disclosed:
Jan 5, 2020

Elegant Themes Divi 3.23 - 4.0.9, Divi Extra 2.23 - 4.0.9, Divi Builder 2.23 - 4.0.9 - PHP Code Injection

high

The Divi Builder, Divi, and Divi Extra plugin and themes for WordPress are vulnerable to PHP Code Injection in versions up to 4.0.10. This allows authenticated attackers to execute code on a vulnerable site's server that could be used to completely take over the site.

CVSS:
8.8
Affected:
2.23 – 4.0.9
Fixed in:
4.0.10
Disclosed:
Jan 4, 2020

Divi Builder [divi-builder] >= 2.23 - <= 4.0.9

unknown

The Divi Builder, Divi, and Divi Extra plugin and themes for WordPress are vulnerable to PHP Code Injection in versions up to 4.0.10. This allows authenticated attackers to execute code on a vulnerable site's server that could be used to completely take over the site.

Affected:
2.23 – 4.0.9
Fixed in:
4.0.9
Disclosed:
Jan 4, 2020

Elegant Themes (Various Versions) - Stored Cross-Site Scripting

medium

The Elegant Themes Divi Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.17.2 in addition to the following themes: Divi <= 3.17.2 and Extra <= 2.17.2 due to insufficient input sanitization and output escaping in the post builder. This makes it possible for au...

CVSS:
6.4
Affected:
up to 2.17.2
Fixed in:
2.17.3
Disclosed:
Oct 30, 2018

Divi Builder [divi-builder] < 2.17.3

unknown

The Elegant Themes Divi Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.17.2 in addition to the following themes: Divi <= 3.17.2 and Extra <= 2.17.2 due to insufficient input sanitization and output escaping in the post builder. This makes it possible for au...

Affected:
up to 2.17.3
Fixed in:
2.17.3
Disclosed:
Oct 30, 2018

Divi Builder [divi-builder] < 1.2.4

unknown

WordPress Elegant Themes' products, such as Divi Builder, Divi, Extra and Divi 2.3, are prone to a privilege escalation vulnerability. Update the theme.

Affected:
up to 1.2.4
Fixed in:
1.2.4
Disclosed:
Feb 18, 2016

Elegant Themes Monarch < 1.2.7 - Privilege Escalation

high

The Elegant Themes Monarch plugin before 1.2.7 for WordPress has privilege escalation.

CVSS:
8.8
Affected:
up to 1.2.3
Fixed in:
1.2.4
Disclosed:
Feb 17, 2016

CVE-2016-11004 on NVD →

Divi Builder [divi-builder] < 1.2.4

unknown
Affected:
up to 1.2.4
Fixed in:
1.2.4

Divi Builder [divi-builder] < 4.0.10

unknown

&quot;A code injection vulnerability was discovered by our team during a routine code audit that could allow logged in contributors, authors and editors to execute a small set of PHP functions.&quot; Affected: Divi version 3.23 and above, Extra 2.23 and above Divi Builder version 2.23 and above. Product versio...

Affected:
up to 4.0.10
Fixed in:
4.0.10

Divi Builder [divi-builder] < 2.17.3

unknown

A privilege escalation vulnerability was discovered that could allow low level users, such as Authors, to use unfiltered HTML inside of post content when using the Divi Builder. Using such code in posts is typically reserved for admins.

Affected:
up to 2.17.3
Fixed in:
2.17.3

Divi Builder [divi-builder] < 4.27.2

unknown

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin&#039;s bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contribu...

Affected:
up to 4.27.2
Fixed in:
4.27.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database