WordPress · Divi · CVE-2026-13712
**Name of the Vulnerable Software and Affected Versions**
Divi WordPress theme versions prior to 5.9.0
**Description**
Insufficient escaping of settings within the Social Media Follow module allows users with contributor privileges to inject JavaScript into link attributes. This stored cross-site scripting (XSS) occurs when a user with higher privileges, such as an administrator, views the affected post.
**Recommendations**
Update Divi WordPress theme to version 5.9.0 or later.