PT-2026-95737 · WordPress · Divi Essentials
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Divi Essential versions prior to 5.8.2
Description
The Divi Essential plugin for WordPress allows authenticated attackers with Subscriber-level access and above to expose sensitive information. The issue exists within the
dnxte get database tables and dnxte get database data AJAX actions. The handlers only verify a nonce if the nonce POST parameter is present, allowing the check to be bypassed by omitting the parameter. Additionally, the plugin fails to call current user can() or enforce any specific capabilities. This enables attackers to enumerate all tables in the WordPress database and read a caller-controlled number of rows from any table, including wp users (usernames, emails, hashed passwords), wp usermeta (session tokens, secret keys), and wp options (privileged settings, API keys, and credentials from other plugins).Recommendations
Update the plugin to a version newer than 5.8.1.
As a temporary workaround, restrict access to the
dnxte get database tables and dnxte get database data AJAX actions.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Divi Essentials