An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side.

Project Subscriptions

Vendors Products
Elegantthemes Subscribe
Divi Builder Subscribe
Divi Extra Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2020-23528 An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 03 Feb 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Elegantthemes
Elegantthemes divi
Elegantthemes divi Builder
Elegantthemes divi Extra
CPEs cpe:2.3:a:elegant_themes:divi:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:elegant_themes:divi_builder:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:elegant_themes:divi_extra:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:elegantthemes:divi:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:elegantthemes:divi_builder:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:elegantthemes:divi_extra:*:*:*:*:*:wordpress:*:*
Vendors & Products Elegant Themes
Elegant Themes divi
Elegant Themes divi Builder
Elegant Themes divi Extra
Elegantthemes
Elegantthemes divi
Elegantthemes divi Builder
Elegantthemes divi Extra

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T17:16:13.484Z

Reserved: 2021-01-01T00:00:00

Link: CVE-2020-35945

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-01-01T04:15:13.307

Modified: 2026-02-03T20:05:28.790

Link: CVE-2020-35945

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses