theme

Extra Vulnerabilities

15 known security issues reported for the Extra WordPress theme. Most recent disclosed Jul 2, 2025.

3 high 3 medium

Running Extra on your site? Check whether your installed version is affected.

Scan your site free

Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library

medium

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-l...

CVSS:
6.4
Affected:
up to 4.27.1
Fixed in:
4.27.2
Disclosed:
Jul 2, 2025

CVE-2024-5647 on NVD →

Extra [extra] < 4.25.1

unknown

[en] The Elegant Themes Divi theme, Extra theme, and Divi Page Builder plugin for WordPress are vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘title’ parameter in versions up to, and including, 4.25.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated atta...

Affected:
up to 4.25.1
Fixed in:
4.25.1
Disclosed:
May 10, 2024

CVE-2024-4490 on NVD →

Elegant Themes Divi Theme, Extra Theme, Divi Page Builder <= 4.25.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

medium

The Elegant Themes Divi theme, Extra theme, and Divi Page Builder plugin for WordPress are vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘title’ parameter in versions up to, and including, 4.25.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...

CVSS:
6.4
Affected:
up to 4.25.0
Fixed in:
4.25.1
Disclosed:
May 9, 2024

CVE-2024-4490 on NVD →

Extra [extra] >= 2.0 - <= 4.5.2

unknown

[en] An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side.

Affected:
2.0 – 4.5.2
Fixed in:
4.5.2
Disclosed:
Jan 1, 2021

CVE-2020-35945 on NVD →

Elegant Themes (Multiple Versions) - Arbitrary File Upload

high

An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side rather than se...

CVSS:
8.8
Affected:
up to 4.3.2
Fixed in:
4.5.3
Disclosed:
Aug 3, 2020

CVE-2020-35945 on NVD →

Extra [extra] < 4.0.10

unknown

Authenticated Code Injection vulnerability found in WordPress Extra premium theme (versions <= 4.0.9).

Affected:
up to 4.0.10
Fixed in:
4.0.10
Disclosed:
Jan 5, 2020

Elegant Themes Divi 3.23 - 4.0.9, Divi Extra 2.23 - 4.0.9, Divi Builder 2.23 - 4.0.9 - PHP Code Injection

high

The Divi Builder, Divi, and Divi Extra plugin and themes for WordPress are vulnerable to PHP Code Injection in versions up to 4.0.10. This allows authenticated attackers to execute code on a vulnerable site's server that could be used to completely take over the site.

CVSS:
8.8
Affected:
2.23 – 4.0.9
Fixed in:
4.0.10
Disclosed:
Jan 4, 2020

Extra [extra] >= 2.23 - <= 4.0.9

unknown

The Divi Builder, Divi, and Divi Extra plugin and themes for WordPress are vulnerable to PHP Code Injection in versions up to 4.0.10. This allows authenticated attackers to execute code on a vulnerable site's server that could be used to completely take over the site.

Affected:
2.23 – 4.0.9
Fixed in:
4.0.9
Disclosed:
Jan 4, 2020

Extra [extra] < 1.2.4

unknown

[en] The Elegant Themes Extra theme before 1.2.4 for WordPress has privilege escalation.

Affected:
up to 1.2.4
Fixed in:
1.2.4
Disclosed:
Sep 20, 2019

CVE-2016-11002 on NVD →

Elegant Themes (Various Versions) - Stored Cross-Site Scripting

medium

The Elegant Themes Divi Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.17.2 in addition to the following themes: Divi <= 3.17.2 and Extra <= 2.17.2 due to insufficient input sanitization and output escaping in the post builder. This makes it possible for au...

CVSS:
6.4
Affected:
up to 2.17.2
Fixed in:
2.17.3
Disclosed:
Oct 30, 2018

Extra [extra] < 2.17.3

unknown

The Elegant Themes Divi Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.17.2 in addition to the following themes: Divi <= 3.17.2 and Extra <= 2.17.2 due to insufficient input sanitization and output escaping in the post builder. This makes it possible for au...

Affected:
up to 2.17.3
Fixed in:
2.17.3
Disclosed:
Oct 30, 2018

ElegantThemes <= 1.2.3 - Privilege Escalation

high

The ElegantThemes Extra theme for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.2.3. This is due to the disclosure of sensitive information which can be used for the vulnerability at hand. This makes it possible for authenticated attackers to access otherwise restricted permissions...

CVSS:
8.8
Affected:
up to 1.2.3
Fixed in:
1.2.4
Disclosed:
Feb 18, 2016

CVE-2016-11002 on NVD →

Extra [extra] < 1.2.4

unknown

WordPress Elegant Themes' products, such as Divi Builder, Divi, Extra and Divi 2.3, are prone to a privilege escalation vulnerability. Update the theme.

Affected:
up to 1.2.4
Fixed in:
1.2.4
Disclosed:
Feb 18, 2016

Extra [extra] < 1.2.4

unknown
Affected:
up to 1.2.4
Fixed in:
1.2.4

Extra [extra] < 4.27.2

unknown

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin&#039;s bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contribu...

Affected:
up to 4.27.2
Fixed in:
4.27.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database