elegantthemes Vulnerabilities and Affected Products
Vulnerabilities associated with divi.
Products
Clear product- divi2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2020-35945CRITICAL | elegantthemes divi Unrestricted Upload of File with Dangerous TypeAn issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side. CWE-434Jan 1, 2021 | CVSS9.9v3.1 | EPSS2.42% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
elegantthemes divi Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image action to wp-admin/admin-ajax.php. NOTE: this vulnerability may be a duplicate of CVE-2014-9734. | CVSS5.0v2.0 | EPSS22.1% | PoCs4 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |