Divi Form Builder <= 5.1.8 - Authenticated (Subscriber+) Missing Authorization to Privilege Escalation via User Profile Update Form
high
The Divi Form Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.1.8. This is due to the update_user() function accepting a user ID parameter from form submissions without verifying that the authenticated user has permission to edit that specific user account, and th...
- CVSS:
- 8.8
- Affected:
- up to 5.1.8
- Fixed in:
- 5.1.9
- Disclosed:
- Jul 8, 2026
CVE-2026-5523 on NVD →
Divi Form Builder <= 5.1.8 - Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via 'acceptFileTypes' Parameter
critical
The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and including 5.1.8. This is due to insufficient file extension validation in the do_image_upload() function where user-supplied input from the acceptFileTypes POST parameter is direc...
- CVSS:
- 9.8
- Affected:
- up to 5.1.8
- Fixed in:
- 5.1.9
- Disclosed:
- Jul 1, 2026
CVE-2026-5524 on NVD →
Divi Form Builder <= 5.1.2 - Unauthenticated Privilege Escalation via 'role'
critical
The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2. This is due to the plugin accepting a user-controlled 'role' parameter from POST data during user registration without validating it against the form's configured default_user_role setting. This mak...
- CVSS:
- 9.8
- Affected:
- up to 5.1.2
- Fixed in:
- 5.1.3
- Disclosed:
- May 20, 2026
CVE-2026-5118 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database