Sensitive Information Exposure in Divi Essential Plugin for WordPress
CVE-2026-15760
6.5MEDIUM
What is CVE-2026-15760?
The Divi Essential plugin for WordPress allows authenticated users with Subscriber-level access or higher to expose sensitive information due to insufficient nonce verification and lack of capability checks in its AJAX actions. Attackers can potentially enumerate all database tables and read user-related data such as usernames, emails, hashed passwords, and more, which could lead to unauthorized access and exploitation of user accounts and sensitive settings stored by other plugins.
Affected Version(s)
Divi Essentials 0 <= 5.8.1