Stored Cross-Site Scripting Vulnerability in Divi Theme for WordPress
CVE-2026-3851

6.4MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-3851?

The Divi theme for WordPress has a vulnerability that allows for stored cross-site scripting, exploiting the legacy JSON format within the Dynamic Content feature. Two primary flaws contribute to this issue: first, the sanitization filter et_builder_sanitize_dynamic_content_fields() only identifies content markers in a specific format, inadvertently leaving the legacy JSON format unfiltered. Second, the method used to resolve meta keys overlooks applying necessary sanitization when certain conditions are met, allowing authenticated users with Contributor-level access or higher to insert malicious scripts. These scripts can execute upon user access, posing significant risks to website integrity and user safety.

Affected Version(s)

Divi 0 <= 4.27.6

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Osvaldo Noe Gonzalez Del Rio (Os)
.