Impact
The Divi WordPress theme for versions 5.0–5.8.1 fails to escape certain settings within the Social Media Follow module before they appear in link attributes. This flaw lets a user with a contributor role embed arbitrary JavaScript that will execute when an administrator or other higher‑privileged user views the affected post. The stored script runs in the context of the site and can hijack the administrator’s session, deface the site, or exfiltrate data, exploiting a Common Weakness Enumeration identified as improper output neutralization (CWE-79).
Affected Systems
The vulnerability affects the Divi theme for WordPress, specifically releases 5.0 through 5.8.1. Users running an older Divi version without the listed patch have the potential to inject JavaScript via the Social Media Follow module, regardless of whether they are site creators or administrators.
Risk and Exploitability
Because the attack can be carried out by a contributor—a role commonly available to content creators—the privilege requirement is low and the impact is significant. Although no official CVSS or EPSS score is supplied, the nature of stored cross‑site scripting implies high severity. The vulnerability has not been recorded in the CISA KEV catalog, but the ability to execute code within an administrator’s session creates a high risk to site integrity and confidentiality.
OpenCVE Enrichment