Remote Code Execution Vulnerability in Divi-Dash Plugin from Elegant Themes
CVE-2026-14321
Key Information:
Badges
What is CVE-2026-14321?
The Divi-Dash plugin for WordPress, versions prior to 1.0.7, features a vulnerability that fails to validate the source of the client IP address used for rate limiting and banning. This design flaw enables unauthorized attackers to spoof arbitrary IP addresses. By exploiting this weakness, attackers can bypass rate limiting mechanisms, ban specific addresses, and potentially escalate stored options indefinitely, leading to a denial of service scenario. Website administrators using the affected versions are strongly advised to upgrade to mitigate these risks.
Affected Version(s)
divi-dash 0 < 1.0.7
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.