Stored Cross-Site Scripting Vulnerability in Divi Theme by WordPress
CVE-2026-3850

6.4MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-3850?

The Divi theme for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability through the redirect_url parameter of the et_pb_contact_form shortcode. This issue exists in all versions up to 4.27.6, resulting from improper sanitization of the redirect_url attribute. Instead of utilizing esc_url(), it is mistakenly sanitized using esc_attr(), allowing for executable arbitrary JavaScript to be injected. When an attacker exploits this vulnerability—after a successful form submission—the injected script can be executed in the context of other users interacting with the page, paving the way for potential malicious activities.

Affected Version(s)

Divi 0 <= 4.27.5

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Osvaldo Noe Gonzalez Del Rio (Os)
.