nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-35945 CVE-2020-35945
CRITICAL
elegantthemes divi Unrestricted Upload of File with Dangerous Type
Record summary
CVE-2020-35945 has a selected CVSS score of 9.9 (critical).
Description
An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Aug 4, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| VulnCheck | Version data not supplied | ||
References
3wpscan.com
https://wpscan.com/vulnerability/10342 wordfence.com
https://www.wordfence.com/blog/2020/08/critical-vulnerability-exposes-over-700000-sites-using-divi-extra-and-divi-builder