theme

Divi Vulnerabilities

20 known security issues reported for the Divi WordPress theme. Most recent disclosed Aug 14, 2026.

2 high 7 medium

Running Divi on your site? Check whether your installed version is affected.

Scan your site free

Divi <= 5.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Divi plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.8.1. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages th...

CVSS:
6.4
Affected:
up to 5.8.1
Fixed in:
5.9.0
Disclosed:
Aug 14, 2026

CVE-2026-13712 on NVD →

Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library

medium

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-l...

CVSS:
6.4
Affected:
up to 4.27.1
Fixed in:
4.27.2
Disclosed:
Jul 2, 2025

CVE-2024-5647 on NVD →

Divi [Divi] < 4.25.2

unknown

[en] The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.25.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that wi...

Affected:
up to 4.25.2
Fixed in:
4.25.2
Disclosed:
Jun 18, 2024

CVE-2024-5533 on NVD →

Divi <= 4.25.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.25.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will ex...

CVSS:
6.4
Affected:
up to 4.25.1
Fixed in:
4.25.2
Disclosed:
Jun 17, 2024

CVE-2024-5533 on NVD →

Divi [Divi] < 4.25.1

unknown

[en] The Elegant Themes Divi theme, Extra theme, and Divi Page Builder plugin for WordPress are vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘title’ parameter in versions up to, and including, 4.25.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated atta...

Affected:
up to 4.25.1
Fixed in:
4.25.1
Disclosed:
May 10, 2024

CVE-2024-4490 on NVD →

Elegant Themes Divi Theme, Extra Theme, Divi Page Builder <= 4.25.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

medium

The Elegant Themes Divi theme, Extra theme, and Divi Page Builder plugin for WordPress are vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘title’ parameter in versions up to, and including, 4.25.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...

CVSS:
6.4
Affected:
up to 4.25.0
Fixed in:
4.25.1
Disclosed:
May 9, 2024

CVE-2024-4490 on NVD →

Divi [Divi] < 4.23.2

unknown

[en] The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'et_pb_text' shortcode in all versions up to, and including, 4.23.1 due to insufficient input sanitization and output escaping on user supplied custom field data. This makes it possible for authenticated attackers, with cont...

Affected:
up to 4.23.2
Fixed in:
4.23.2
Disclosed:
Dec 23, 2023

CVE-2023-6744 on NVD →

Divi <= 4.23.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'et_pb_text' shortcode in all versions up to, and including, 4.23.1 due to insufficient input sanitization and output escaping on user supplied custom field data. This makes it possible for authenticated attackers, with contribut...

CVSS:
6.4
Affected:
up to 4.23.1
Fixed in:
4.23.2
Disclosed:
Dec 22, 2023

CVE-2023-6744 on NVD →

Divi [Divi] < 4.20.3

unknown

[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Elegant themes Divi theme <= 4.20.2 versions.

Affected:
up to 4.20.3
Fixed in:
4.20.3
Disclosed:
Aug 8, 2023

CVE-2023-29099 on NVD →

Divi <= 4.20.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.20.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will e...

CVSS:
6.4
Affected:
up to 4.20.2
Fixed in:
4.20.3
Disclosed:
May 9, 2023

CVE-2023-29099 on NVD →

Divi [Divi] >= 3.0 - <= 4.5.2

unknown

[en] An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side.

Affected:
3.0 – 4.5.2
Fixed in:
4.5.2
Disclosed:
Jan 1, 2021

CVE-2020-35945 on NVD →

Elegant Themes (Multiple Versions) - Arbitrary File Upload

high

An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side rather than se...

CVSS:
8.8
Affected:
up to 4.3.2
Fixed in:
4.5.3
Disclosed:
Aug 3, 2020

CVE-2020-35945 on NVD →

Divi [Divi] < 4.0.10

unknown

Authenticated Code Injection vulnerability found in WordPress Divi premium theme (versions <= 4.0.9).

Affected:
up to 4.0.10
Fixed in:
4.0.10
Disclosed:
Jan 5, 2020

Elegant Themes Divi 3.23 - 4.0.9, Divi Extra 2.23 - 4.0.9, Divi Builder 2.23 - 4.0.9 - PHP Code Injection

high

The Divi Builder, Divi, and Divi Extra plugin and themes for WordPress are vulnerable to PHP Code Injection in versions up to 4.0.10. This allows authenticated attackers to execute code on a vulnerable site's server that could be used to completely take over the site.

CVSS:
8.8
Affected:
3.23 – 4.0.9
Fixed in:
4.0.10
Disclosed:
Jan 4, 2020

Divi [Divi] >= 3.23 - <= 4.0.9

unknown

The Divi Builder, Divi, and Divi Extra plugin and themes for WordPress are vulnerable to PHP Code Injection in versions up to 4.0.10. This allows authenticated attackers to execute code on a vulnerable site's server that could be used to completely take over the site.

Affected:
3.23 – 4.0.9
Fixed in:
4.0.9
Disclosed:
Jan 4, 2020

Elegant Themes (Various Versions) - Stored Cross-Site Scripting

medium

The Elegant Themes Divi Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.17.2 in addition to the following themes: Divi <= 3.17.2 and Extra <= 2.17.2 due to insufficient input sanitization and output escaping in the post builder. This makes it possible for au...

CVSS:
6.4
Affected:
up to 3.17.2
Fixed in:
3.17.3
Disclosed:
Oct 30, 2018

Divi [Divi] < 3.17.3

unknown

The Elegant Themes Divi Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.17.2 in addition to the following themes: Divi <= 3.17.2 and Extra <= 2.17.2 due to insufficient input sanitization and output escaping in the post builder. This makes it possible for au...

Affected:
up to 3.17.3
Fixed in:
3.17.3
Disclosed:
Oct 30, 2018

Divi [Divi] < 2.6.4

unknown

WordPress Elegant Themes' products, such as Divi Builder, Divi, Extra and Divi 2.3, are prone to a privilege escalation vulnerability. Update the theme.

Affected:
up to 2.6.4
Fixed in:
2.6.4
Disclosed:
Feb 18, 2016

Divi [Divi] < 2.6.4

unknown
Affected:
up to 2.6.4
Fixed in:
2.6.4

Divi [Divi] < 4.27.2

unknown

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin&#039;s bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contribu...

Affected:
up to 4.27.2
Fixed in:
4.27.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database