Elegant Themes Divi

6 known vulnerabilities in Elegant Themes Divi, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-91707 CVSS 5.3 medium The The Divi theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.11.1. This is due…
  • CVE-2026-4361 CVSS 5.0 medium The Divi theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.27.6. This is due to the…
  • CVE-2026-3853 CVSS 6.4 medium The Divi theme for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the `image_src` attribute of the…
  • CVE-2026-3852 CVSS 6.4 medium The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `skype_url` shortcode attribute of the Social Media…
  • CVE-2026-3850 CVSS 6.4 medium The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `redirect_url` parameter of the `et_pb_contact_form`…
  • CVE-2026-3851 CVSS 6.4 medium The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Dynamic Content feature's legacy JSON format in all…