• divi2 vulnerabilities

Showing 2 vulnerabilities on this page for divi

Signals CISA KEV Ransomware Nuclei
elegantthemes vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

elegantthemes divi Unrestricted Upload of File with Dangerous Type

An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side.

CWE-434Jan 1, 2021
CVSS9.9v3.1EPSS2.42%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

elegantthemes divi Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image action to wp-admin/admin-ajax.php. NOTE: this vulnerability may be a duplicate of CVE-2014-9734.

CWE-22Feb 11, 20151 related artifact
CVSS5.0v2.0EPSS22.1%PoCs4SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX