Vulnerabilities
Vulnerable Software
Elegant Themes:  Security Vulnerabilities
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Elegant themes Divi theme <= 4.20.2 versions.
CVSS Score
6.5
EPSS Score
0.001
Published
2023-08-08
An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side.
CVSS Score
9.9
EPSS Score
0.022
Published
2021-01-01
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image action to wp-admin/admin-ajax.php. NOTE: this vulnerability may be a duplicate of CVE-2014-9734.
CVSS Score
5.0
EPSS Score
0.721
Published
2015-02-11


Contact Us

Shodan ® - All rights reserved