Stored Cross-Site Scripting Vulnerability in Divi Theme for WordPress
CVE-2026-3851
6.4MEDIUM
What is CVE-2026-3851?
The Divi theme for WordPress has a vulnerability that allows for stored cross-site scripting, exploiting the legacy JSON format within the Dynamic Content feature. Two primary flaws contribute to this issue: first, the sanitization filter et_builder_sanitize_dynamic_content_fields() only identifies content markers in a specific format, inadvertently leaving the legacy JSON format unfiltered. Second, the method used to resolve meta keys overlooks applying necessary sanitization when certain conditions are met, allowing authenticated users with Contributor-level access or higher to insert malicious scripts. These scripts can execute upon user access, posing significant risks to website integrity and user safety.
Affected Version(s)
Divi 0 <= 4.27.6