Impact
The Divi Dash WordPress plugin before version 1.0.7 fails to validate the source of the client IP address used for rate limiting and banning. An attacker can craft requests with an arbitrary spoofed IP address, bypass the rate limiting logic, ban selected addresses, and add entries to a stored option without restraint. This unchecked growth the plugin or the entire website to become unavailable. The flaw is a classic Resource Exhaustion vulnerability, identified as CWE-400.
Affected Systems
Any WordPress installation that includes the divi‑dash plugin with a version earlier than 1.0.7 is impacted. The vendor is listed as Unknown:divi-dash, and the risk applies wherever the rate limiting or banning feature of the plugin is active.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.2, signifying high severity. The EPSS score is currently unavailable and the flaw is not listed in CISA's KEV catalog. Attackers can exploit the issue without authentication by sending crafted HTTP requests to the plugin’s administrative endpoints, using spoofed IP addresses to trigger the bypass and inflate the stored option until the site fails.
OpenCVE Enrichment