SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-13712

MEDIUM · CVSS 5.4 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-16 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The Divi WordPress theme prior to version 5.9.0 is vulnerable due to improper escaping of Social Media Follow module settings, enabling users with contributor roles to inject malicious JavaScript. This script executes when a higher-privileged user, such as an administrator, views the affected post, potentially leading to unauthorized actions or data exposure. WordPress site administrators and developers using the Divi theme should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-13712
Severity
MEDIUM
CVSS
5.4
EPSS
0.16%
WordPress Java

Original NVD Description

The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow module settings before outputting them in link attributes, allowing users with a role as low as contributor to store JavaScript which will run when a higher privileged user, such as an administrator, views the post.