Description
The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow module settings before outputting them in link attributes, allowing users with a role as low as contributor to store JavaScript which will run when a higher privileged user, such as an administrator, views the post.
Published: 2026-08-16
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Divi WordPress theme contains a stored cross‑site scripting flaw located in the Social Media Follow module. The module fails to escape certain link attributes, permitting users with a contributor role to embed JavaScript that will execute when a higher‑privileged user, such as an administrator, views the affected post. This vulnerability enables arbitrary script execution in the context of privileged users.

Affected Systems

The issue affects the Divi WordPress theme for releases 5.0 to 5.8.1, any site still running a pre‑5.9.0 version of the theme. Users with contributor or equivalent roles can inject the malicious payload via the Social Media Follow settings.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity, while the EPSS score of <1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Because the attack can be launched by a contributor—a role often available to content creators—the privilege required is low, but the impact occurs in the context of an admin or higher‑privileged user. Potential risk is moderate due to the combination of low privilege barrier and significance of executing code on trusted accounts.

Generated by OpenCVE AI on August 18, 2026 at 00:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Divi theme to version 5.9.0 or later, where the Social Media Follow module has been properly sanitized.
  • If an immediate update cannot be performed, permanently disable the Social Media Follow module or delete any customized links from the theme settings to prevent execution of stored scripts.
  • Restrict the contributor role or review existing contributor content for malicious scripts, and consider limiting administrative functions to higher‑trusted users.

Generated by OpenCVE AI on August 18, 2026 at 00:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 16 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Sun, 16 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow module settings before outputting them in link attributes, allowing users with a role as low as contributor to store JavaScript which will run when a higher privileged user, such as an administrator, views the post.
Title Divi 5.0 - 5.8.1 - Contributor+ Stored XSS via Social Media Follow Skype URL
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-17T20:15:31.399Z

Reserved: 2026-06-29T13:51:45.117Z

Link: CVE-2026-13712

cve-icon Vulnrichment

Updated: 2026-08-17T20:15:24.534Z

cve-icon NVD

Status : Deferred

Published: 2026-08-16T06:16:50.227

Modified: 2026-08-26T16:30:52.723

Link: CVE-2026-13712

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T01:00:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')