PT-2026-73117 · WordPress · Divi
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Divi WordPress theme versions prior to 5.9.0
Description
Insufficient escaping of settings within the Social Media Follow module allows users with contributor privileges to inject JavaScript into link attributes. This stored cross-site scripting (XSS) occurs when a user with higher privileges, such as an administrator, views the affected post.
Recommendations
Update Divi WordPress theme to version 5.9.0 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Divi