PT-2026-84596 · WordPress · Divi Theme

CVE-2026-3851

·

Published

2026-09-02

·

Updated

2026-09-02

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Divi theme for WordPress versions prior to 4.27.7
Description Stored Cross-Site Scripting is possible via the Dynamic Content feature's legacy JSON format. The issue arises because the save-time sanitization filter et builder sanitize dynamic content fields() only checks for markers in the @ET-DC@...@ format, while the rendering engine supports a legacy JSON format that bypasses this filter. Additionally, the post meta key resolver in et builder filter resolve default dynamic content() fails to apply wp kses post() to the resolved meta value when enable html is set to on, allowing raw get post meta() output to be rendered. Authenticated attackers with Contributor-level access or higher can inject arbitrary web scripts into pages that execute when accessed by other users.
Recommendations Update Divi theme for WordPress to version 4.27.7 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-3851

Affected Products

Divi Theme