Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library
medium
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-l...
- CVSS:
- 6.4
- Affected:
- up to 4.27.1
- Fixed in:
- 4.27.2
- Disclosed:
- Jul 2, 2025
CVE-2024-5647 on NVD →
Extra [extra] < 4.25.1
unknown
[en] The Elegant Themes Divi theme, Extra theme, and Divi Page Builder plugin for WordPress are vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘title’ parameter in versions up to, and including, 4.25.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated atta...
- Affected:
- up to 4.25.1
- Fixed in:
- 4.25.1
- Disclosed:
- May 10, 2024
CVE-2024-4490 on NVD →
Elegant Themes Divi Theme, Extra Theme, Divi Page Builder <= 4.25.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
medium
The Elegant Themes Divi theme, Extra theme, and Divi Page Builder plugin for WordPress are vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘title’ parameter in versions up to, and including, 4.25.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...
- CVSS:
- 6.4
- Affected:
- up to 4.25.0
- Fixed in:
- 4.25.1
- Disclosed:
- May 9, 2024
CVE-2024-4490 on NVD →
Extra [extra] >= 2.0 - <= 4.5.2
unknown
[en] An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side.
- Affected:
- 2.0 – 4.5.2
- Fixed in:
- 4.5.2
- Disclosed:
- Jan 1, 2021
CVE-2020-35945 on NVD →
Elegant Themes (Multiple Versions) - Arbitrary File Upload
high
An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side rather than se...
- CVSS:
- 8.8
- Affected:
- up to 4.3.2
- Fixed in:
- 4.5.3
- Disclosed:
- Aug 3, 2020
CVE-2020-35945 on NVD →
Extra [extra] < 4.0.10
unknown
Authenticated Code Injection vulnerability found in WordPress Extra premium theme (versions <= 4.0.9).
- Affected:
- up to 4.0.10
- Fixed in:
- 4.0.10
- Disclosed:
- Jan 5, 2020
Elegant Themes Divi 3.23 - 4.0.9, Divi Extra 2.23 - 4.0.9, Divi Builder 2.23 - 4.0.9 - PHP Code Injection
high
The Divi Builder, Divi, and Divi Extra plugin and themes for WordPress are vulnerable to PHP Code Injection in versions up to 4.0.10. This allows authenticated attackers to execute code on a vulnerable site's server that could be used to completely take over the site.
- CVSS:
- 8.8
- Affected:
- 2.23 – 4.0.9
- Fixed in:
- 4.0.10
- Disclosed:
- Jan 4, 2020
Extra [extra] >= 2.23 - <= 4.0.9
unknown
The Divi Builder, Divi, and Divi Extra plugin and themes for WordPress are vulnerable to PHP Code Injection in versions up to 4.0.10. This allows authenticated attackers to execute code on a vulnerable site's server that could be used to completely take over the site.
- Affected:
- 2.23 – 4.0.9
- Fixed in:
- 4.0.9
- Disclosed:
- Jan 4, 2020
Extra [extra] < 1.2.4
unknown
[en] The Elegant Themes Extra theme before 1.2.4 for WordPress has privilege escalation.
- Affected:
- up to 1.2.4
- Fixed in:
- 1.2.4
- Disclosed:
- Sep 20, 2019
CVE-2016-11002 on NVD →
Elegant Themes (Various Versions) - Stored Cross-Site Scripting
medium
The Elegant Themes Divi Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.17.2 in addition to the following themes: Divi <= 3.17.2 and Extra <= 2.17.2 due to insufficient input sanitization and output escaping in the post builder. This makes it possible for au...
- CVSS:
- 6.4
- Affected:
- up to 2.17.2
- Fixed in:
- 2.17.3
- Disclosed:
- Oct 30, 2018
Extra [extra] < 2.17.3
unknown
The Elegant Themes Divi Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.17.2 in addition to the following themes: Divi <= 3.17.2 and Extra <= 2.17.2 due to insufficient input sanitization and output escaping in the post builder. This makes it possible for au...
- Affected:
- up to 2.17.3
- Fixed in:
- 2.17.3
- Disclosed:
- Oct 30, 2018
ElegantThemes <= 1.2.3 - Privilege Escalation
high
The ElegantThemes Extra theme for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.2.3. This is due to the disclosure of sensitive information which can be used for the vulnerability at hand. This makes it possible for authenticated attackers to access otherwise restricted permissions...
- CVSS:
- 8.8
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.4
- Disclosed:
- Feb 18, 2016
CVE-2016-11002 on NVD →
Extra [extra] < 1.2.4
unknown
WordPress Elegant Themes' products, such as Divi Builder, Divi, Extra and Divi 2.3, are prone to a privilege escalation vulnerability.
Update the theme.
- Affected:
- up to 1.2.4
- Fixed in:
- 1.2.4
- Disclosed:
- Feb 18, 2016
Extra [extra] < 1.2.4
unknown
- Affected:
- up to 1.2.4
- Fixed in:
- 1.2.4
Extra [extra] < 4.27.2
unknown
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contribu...
- Affected:
- up to 4.27.2
- Fixed in:
- 4.27.2
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database