Remote Code Execution Vulnerability in Divi-Dash Plugin from Elegant Themes
CVE-2026-14321

Currently unrated

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
23 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-14321?

The Divi-Dash plugin for WordPress, versions prior to 1.0.7, features a vulnerability that fails to validate the source of the client IP address used for rate limiting and banning. This design flaw enables unauthorized attackers to spoof arbitrary IP addresses. By exploiting this weakness, attackers can bypass rate limiting mechanisms, ban specific addresses, and potentially escalate stored options indefinitely, leading to a denial of service scenario. Website administrators using the affected versions are strongly advised to upgrade to mitigate these risks.

Affected Version(s)

divi-dash 0 < 1.0.7

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mike Gozdiskowski
WPScan
.