Stored Cross-Site Scripting Vulnerability in Divi Theme by WordPress
CVE-2026-3850
6.4MEDIUM
What is CVE-2026-3850?
The Divi theme for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability through the redirect_url parameter of the et_pb_contact_form shortcode. This issue exists in all versions up to 4.27.6, resulting from improper sanitization of the redirect_url attribute. Instead of utilizing esc_url(), it is mistakenly sanitized using esc_attr(), allowing for executable arbitrary JavaScript to be injected. When an attacker exploits this vulnerability—after a successful form submission—the injected script can be executed in the context of other users interacting with the page, paving the way for potential malicious activities.
Affected Version(s)
Divi 0 <= 4.27.5