PT-2026-84596 · WordPress · Divi Theme
CVE-2026-3851
·
Published
2026-09-02
·
Updated
2026-09-02
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Divi theme for WordPress versions prior to 4.27.7
Description
Stored Cross-Site Scripting is possible via the Dynamic Content feature's legacy JSON format. The issue arises because the save-time sanitization filter
et builder sanitize dynamic content fields() only checks for markers in the @ET-DC@...@ format, while the rendering engine supports a legacy JSON format that bypasses this filter. Additionally, the post meta key resolver in et builder filter resolve default dynamic content() fails to apply wp kses post() to the resolved meta value when enable html is set to on, allowing raw get post meta() output to be rendered. Authenticated attackers with Contributor-level access or higher can inject arbitrary web scripts into pages that execute when accessed by other users.Recommendations
Update Divi theme for WordPress to version 4.27.7 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Divi Theme