PT-2026-95737 · WordPress · Divi Essentials

·

CVE-2026-15760

·

Published

2026-09-19

·

Updated

2026-09-19

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Divi Essential versions prior to 5.8.2
Description The Divi Essential plugin for WordPress allows authenticated attackers with Subscriber-level access and above to expose sensitive information. The issue exists within the dnxte get database tables and dnxte get database data AJAX actions. The handlers only verify a nonce if the nonce POST parameter is present, allowing the check to be bypassed by omitting the parameter. Additionally, the plugin fails to call current user can() or enforce any specific capabilities. This enables attackers to enumerate all tables in the WordPress database and read a caller-controlled number of rows from any table, including wp users (usernames, emails, hashed passwords), wp usermeta (session tokens, secret keys), and wp options (privileged settings, API keys, and credentials from other plugins).
Recommendations Update the plugin to a version newer than 5.8.1. As a temporary workaround, restrict access to the dnxte get database tables and dnxte get database data AJAX actions.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15760

Affected Products

Divi Essentials