Description
The Divi Essential plugin for WordPress is vulnerable to sensitive information exposure in versions up to, and including, 5.8.1 via the dnxte_get_database_tables and dnxte_get_database_data AJAX actions. The handlers only conditionally verify a nonce (the check runs solely when the 'nonce' POST parameter is present and can be trivially bypassed by omitting the parameter) and never call current_user_can() or otherwise enforce a capability. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enumerate every table in the WordPress database and read up to a caller-controlled number of rows from any table — including wp_users (usernames, emails, hashed passwords), wp_usermeta (session tokens, secret keys), and wp_options (privileged settings, API keys, credentials stored by other plugins).
Published: 2026-09-19
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Disclosure
Action: Immediate Upgrade
AI Analysis

Impact

The Divi Essentials plugin for WordPress contains a flaw that allows authenticated users with Subscriber-level access or higher to bypass nonce validation and perform sensitive operations without any capability checks. As a result, these users can enumerate all database tables and read any number of rows from each table, gaining access to usernames, emails, hashed passwords, session tokens, secret keys, and other privileged settings stored in wp_options. This constitutes a direct breach of confidentiality that could compromise user accounts and expose sensitive configuration data.

Affected Systems

WordPress sites running the Divi Essentials plugin version 5.8.1 or earlier are affected. Any installation of the plugin at or below this release is vulnerable until it is upgraded past 5.8.1.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA KEV, so public exploitation evidence is lacking. Nevertheless, the flaw requires only an authenticated account with Subscriber or higher privileges, and once obtained the attacker can easily issue HTTP requests to the vulnerable AJAX actions to enumerate tables and read sensitive data. The lack of a capability check removes the need for privilege escalation, making the attack path straightforward for any site that has exposed or weakly protected administrative or subscriber accounts.

Generated by OpenCVE AI on September 19, 2026 at 10:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Divi Essentials to version 5.8.2 or later, which removes the missing authorization checks on the dnxte_get_database_tables and dnxte_get_database_data AJAX actions.
  • If an immediate upgrade is not possible, deactivate or delete the Divi Essentials plugin to eliminate the exposed endpoints.
  • Restrict Subscriber and lower user roles from accessing the Divi Essentials AJAX actions, for example by adding a capability check or using a WordPress plugin that blocks these requests.
  • Perform a selective scan of the WordPress AJAX endpoints to confirm the endpoints are no longer accessible without proper capability.

Generated by OpenCVE AI on September 19, 2026 at 10:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Divi Essential
Divi Essential divi Essentials
Wordpress
Wordpress wordpress
Vendors & Products Divi Essential
Divi Essential divi Essentials
Wordpress
Wordpress wordpress

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description The Divi Essential plugin for WordPress is vulnerable to sensitive information exposure in versions up to, and including, 5.8.1 via the dnxte_get_database_tables and dnxte_get_database_data AJAX actions. The handlers only conditionally verify a nonce (the check runs solely when the 'nonce' POST parameter is present and can be trivially bypassed by omitting the parameter) and never call current_user_can() or otherwise enforce a capability. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enumerate every table in the WordPress database and read up to a caller-controlled number of rows from any table — including wp_users (usernames, emails, hashed passwords), wp_usermeta (session tokens, secret keys), and wp_options (privileged settings, API keys, credentials stored by other plugins).
Title Divi Essentials <= 5.8.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via dnxte_get_database_data AJAX Action
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Divi Essential Divi Essentials
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:01:27.277Z

Reserved: 2026-07-14T17:23:31.755Z

Link: CVE-2026-15760

cve-icon Vulnrichment

Updated: 2026-09-19T13:58:18.158Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T03:17:13.867

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-15760

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:03:45Z

Weaknesses