Impact
The Divi Essentials plugin for WordPress contains a flaw that allows authenticated users with Subscriber-level access or higher to bypass nonce validation and perform sensitive operations without any capability checks. As a result, these users can enumerate all database tables and read any number of rows from each table, gaining access to usernames, emails, hashed passwords, session tokens, secret keys, and other privileged settings stored in wp_options. This constitutes a direct breach of confidentiality that could compromise user accounts and expose sensitive configuration data.
Affected Systems
WordPress sites running the Divi Essentials plugin version 5.8.1 or earlier are affected. Any installation of the plugin at or below this release is vulnerable until it is upgraded past 5.8.1.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA KEV, so public exploitation evidence is lacking. Nevertheless, the flaw requires only an authenticated account with Subscriber or higher privileges, and once obtained the attacker can easily issue HTTP requests to the vulnerable AJAX actions to enumerate tables and read sensitive data. The lack of a capability check removes the need for privilege escalation, making the attack path straightforward for any site that has exposed or weakly protected administrative or subscriber accounts.
OpenCVE Enrichment