CVE-2026-2626

HIGH

Divi-Booster <5.0.2 - CSRF & Object Injection

Title source: llm

Description

The divi-booster WordPress plugin before 5.0.2 does not have authorization and CSRF checks in one of its fixing function, allowing unauthenticated users to modify stored divi-booster WordPress plugin before 5.0.2 options. Furthermore, due to the use of unserialize() on the data, this could be further exploited when combined with a PHP gadget chain to achieve PHP Object Injection

Scores

CVSS v3 8.1
EPSS 0.0001
EPSS Percentile 2.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502 CWE-352
Status draft

Timeline

Published Mar 11, 2026
Tracked Since Mar 11, 2026