Description
The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.02 via the 'et_pb_text' shortcode 'cvdb_content_visibility_check' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.
Published: 2026-06-02
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Content Visibility for Divi Builder plugin for WordPress contains an injection flaw in its 'et_pb_text' shortcode, where the 'cvdb_content_visibility_check' parameter can be abused to run arbitrary code on the server. The flaw is triggered only when the parameter is processed and evaluated, effectively allowing an attacker to inject code. The impact of this vulnerability is complete compromise of the hosting environment, as an attacker could modify files, exfiltrate data, or install persistent backdoors. The weakness is categorized as improper code injection (CWE-94).

Affected Systems

The vulnerability affects the jhorowitz package 'Content Visibility for Divi Builder' in WordPress, specifically all releases up to and including version 4.02. Any site running any of those releases is susceptible. Upgrading to a newer release beyond 4.02 resolves the issue. No other WordPress core components or third‑party plugins are listed in the CVE as affected.

Risk and Exploitability

The CVSS score of 8.8 labels this flaw as high severity. The EPSS score is not available, making the current likelihood of exploitation uncertain, but the absence of a KEV listing does not diminish the potential threat to systems with Contributor or higher roles. Attackers would need authenticated Contributor-level access, after which they can insert the malicious shortcode into a post or page. Once executed, code runs under the web server’s privileges. The lack of an automated exploitation pathway and the need for authenticated access somewhat lowers the risk relative to unauthenticated vectors, yet the impact warrants urgent attention.

Generated by OpenCVE AI on June 3, 2026 at 03:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Content Visibility for Divi Builder to the latest release (≥4.03) which removes the vulnerable shortcode handling.
  • If an immediate update cannot be applied, temporarily disable or delete the plugin to eliminate the attack surface.
  • Restrict Contributor-level permissions so that contributors cannot add or edit content containing the affected shortcode until the patch is deployed.
  • Audit existing content for the 'cvdb_content_visibility_check' parameter, and sanitize or delete any instances containing malicious payloads.

Generated by OpenCVE AI on June 3, 2026 at 03:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 03 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
Description The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.02 via the 'et_pb_text' shortcode 'cvdb_content_visibility_check' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.
Title Content Visibility for Divi Builder <= 4.02 - Authenticated (Contributor+) Remote Code Execution
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-06-02T17:28:25.213Z

Reserved: 2026-02-03T14:31:46.015Z

Link: CVE-2026-1829

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-02T20:16:33.477

Modified: 2026-06-02T20:16:33.477

Link: CVE-2026-1829

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-03T04:00:13Z

Weaknesses