Elegant Themes (Multiple Versions) - Arbitrary File Upload

2020-08-03 00:00
Chloe Chamberland

Strategic Overview

Status
Patched in 4.5.3
Affected PluginDivi Builder
Affected Version<= 4.3.2
CVSS8.8High
CVECVE-2020-35945
View all Divi Builder vulnerabilities

Vulnerability Overview

An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side rather than server side.

Technical Analysis

REMEDIATION: Update to version 4.5.3, or a newer patched version --- IDENTIFIER: CWE-434 (Unrestricted Upload of File with Dangerous Type) The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C