Arbitrary File Upload Vulnerability in Divi Builder and Divi Theme by Elegant Themes
CVE-2020-35945
9.9CRITICAL
What is CVE-2020-35945?
A vulnerability exists in the Divi Builder plugin, along with the Divi theme and Divi Extra theme, that allows authenticated users with contributor-level permissions or higher to upload arbitrary files, including potentially malicious PHP files. This exploitation occurs due to an insufficient server-side validation process, as the file extension checks are handled on the client side. This flaw can significantly compromise site security, enabling attackers to execute code on the server and gain unauthorized access or control over the site.