SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-3851

MEDIUM · CVSS 6.4 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient sanitization of dynamic content, allowing authenticated attackers with Contributor-level access or higher to inject malicious scripts. This vulnerability can lead to the execution of arbitrary web scripts on affected pages, posing a risk to users who access these pages. WordPress site administrators using the Divi theme should prioritize patching this vulnerability to protect their sites and users from potential exploitation.

CVE
CVE-2026-3851
Severity
MEDIUM
CVSS
6.4
EPSS
0.17%
WordPress

Original NVD Description

The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Dynamic Content feature's legacy JSON format in all versions up to, and including, 4.27.6. This is due to two compounding flaws: (1) the save-time sanitization filter `et_builder_sanitize_dynamic_content_fields()` only searches for dynamic content markers in the `@ET-DC@...@` format, but the rendering engine also supports a legacy JSON format that is silently converted at render time, completely bypassing the save-time filter, and (2) the `post_meta_key` resolver in `et_builder_filter_resolve_default_dynamic_content()` does not apply `wp_kses_post()` to the resolved meta value when `enable_html` is set to `on`, passing raw `get_post_meta()` output directly to the page. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.