Impact
The Divi WordPress theme contains a stored cross‑site scripting flaw located in the Social Media Follow module. The module fails to escape certain link attributes, permitting users with a contributor role to embed JavaScript that will execute when a higher‑privileged user, such as an administrator, views the affected post. This vulnerability enables arbitrary script execution in the context of privileged users.
Affected Systems
The issue affects the Divi WordPress theme for releases 5.0 to 5.8.1, any site still running a pre‑5.9.0 version of the theme. Users with contributor or equivalent roles can inject the malicious payload via the Social Media Follow settings.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, while the EPSS score of <1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Because the attack can be launched by a contributor—a role often available to content creators—the privilege required is low, but the impact occurs in the context of an admin or higher‑privileged user. Potential risk is moderate due to the combination of low privilege barrier and significance of executing code on trusted accounts.
OpenCVE Enrichment