Record summary

CVE-2020-35945 has a selected CVSS score of 9.9 (critical).

Description

An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Aug 4, 2020 · VulnCheck
Reported exploitation
Observed · VulnCheck

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

References

3