Divi

Divi has 14 disclosed vulnerabilities in the WordSec catalog, reported between 2018 and 2026; all 14 are fixed as of September 2026. Their average CVSS score is 6.6, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 2 high. 2026 was the busiest year with 6 disclosures.

The most common weakness is Cross-Site Scripting, behind 10 of the records (71%). Other recurring categories include Code Injection, Improper Input Validation.

Every one of the 14 issues recorded for Divi has a vendor fix available, so running the current release closes all known holes.

8 independent researchers contributed these findings, most of them (5) reported by Osvaldo Noe Gonzalez Del Rio (Os).

01234567891030.10.2018Today30.10.20186.4Elegant Themes (Various Versions) - Stored Cross-Site Scripting CVSS 6.4 · 30.10.201804.01.20208.8Elegant Themes Divi 3.23 - 4.0.9, Divi Extra 2.23 - 4.0.9, Divi Builder 2.23 - 4.0.9 - PHP Code Injection CVSS 8.8 · 04.01.202003.08.20208.8Elegant Themes (Multiple Versions) - Arbitrary File Upload CVSS 8.8 · 03.08.202009.05.20236.4Divi <= 4.20.2 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 09.05.202322.12.20236.4Divi <= 4.23.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CVSS 6.4 · 22.12.202309.05.20246.4Elegant Themes Divi Theme, Extra Theme, Divi Page Builder <= 4.25.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting CVSS 6.4 · 09.05.202417.06.20246.4Divi <= 4.25.1 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 17.06.202402.07.20256.4Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library CVSS 6.4 · 02.07.202514.08.20266.4Divi 5.0 - 5.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting CVSS 6.4 · 14.08.202601.09.20266.4Divi <= 4.27.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Dynamic Content (Legacy JSON Format) Shortcode CVSS 6.4 · 01.09.20266.4Divi <= 4.27.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Contact Form 'redirect_url' Shortcode Parameter CVSS 6.4 · 01.09.202602.09.20266.4Divi <= 4.27.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Social Media Follow 'skype_url' Shortcode Parameter CVSS 6.4 · 02.09.202604.09.20265.0Divi <= 4.27.6 - Authenticated (Contributor+) Server-Side Request Forgery via 'image_src' Parameter CVSS 5.0 · 04.09.20266.4Divi <= 4.27.6 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Video Slider 'image_src' Shortcode Parameter CVSS 6.4 · 04.09.2026

Strategic Overview

Avg CVSSMedium
6.6/ 10
Patch Coverage100%
Open

0

Fixed

14

Get automatic notifications for all Divi vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2020-35945

Elegant Themes (Multiple Versions) - Arbitrary File Upload

Read the full analysis

Vulnerability Records

14 records
2026-09-04 18:15CVE-2026-3853
6.4
Medium
Osvaldo Noe Gonzalez Del Rio (Os)Yes
2026-09-04 18:13CVE-2026-4361
5.0
Medium
Osvaldo Noe Gonzalez Del Rio (Os)Yes
2026-09-02 19:51CVE-2026-3852
6.4
Medium
Osvaldo Noe Gonzalez Del Rio (Os)Yes
2026-09-01 17:38CVE-2026-3850
6.4
Medium
Osvaldo Noe Gonzalez Del Rio (Os)Yes
2026-09-01 14:46CVE-2026-3851
6.4
Medium
Osvaldo Noe Gonzalez Del Rio (Os)Yes
2026-08-14 00:00CVE-2026-13712
6.4
Medium
.$nYes
2025-07-02 00:00CVE-2024-5647
6.4
Medium
WebbernautYes
2024-06-17 19:31CVE-2024-5533
6.4
Medium
Ngô Thiên An (ancorn_)Yes
2024-05-09 00:00CVE-2024-4490
6.4
Medium
WebbernautYes
2023-12-22 00:00CVE-2023-6744
6.4
Medium
Francesco CarlucciYes
Showing 1–10 of 14 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C