Description
The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Dynamic Content feature's legacy JSON format in all versions up to, and including, 4.27.6. This is due to two compounding flaws: (1) the save-time sanitization filter `et_builder_sanitize_dynamic_content_fields()` only searches for dynamic content markers in the `@ET-DC@...@` format, but the rendering engine also supports a legacy JSON format that is silently converted at render time, completely bypassing the save-time filter, and (2) the `post_meta_key` resolver in `et_builder_filter_resolve_default_dynamic_content()` does not apply `wp_kses_post()` to the resolved meta value when `enable_html` is set to `on`, passing raw `get_post_meta()` output directly to the page. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-09-02
Score: 6.4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Divi theme contains a stored cross‑site scripting flaw that allows authenticated users with Contributor access or higher to embed arbitrary JavaScript into page markup. The vulnerability arises from two flaws: a save‑time sanitizer that only checks for a specific dynamic content marker format, and a resolver that fails to apply proper output sanitization when legacy JSON formatted content is rendered. The affected code path results in the injected script executing whenever any site visitor loads the compromised page, thereby compromising the integrity and confidentiality of the site for end users.

Affected Systems

Elegant Themes Divi for WordPress, versions up through and including 4.27.6. All installs of this theme within that version range are susceptible, regardless of WordPress core or other plugins.

Risk and Exploitability

The overall CVSS score is 6.4, indicating a moderate impact. The EPSS score is unavailable, so the precise likelihood of exploitation in the wild cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed exploitation in the broader threat landscape yet. Attackers would need valid credentials that grant Contributor‑level editing rights to inject payloads via the Dynamic Content legacy JSON format. Once inserted, the payload persists across page loads until manually removed or the theme is upgraded.

Generated by OpenCVE AI on September 2, 2026 at 05:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Divi 4.27.7 or later, which removes the vulnerable dynamic content handling logic.
  • If an upgrade is not immediately possible, delete or neutralize all legacy JSON dynamic content from the site, ensuring that any JavaScript blocks have been removed from the editor panes before publishing.
  • Clear all caching mechanisms, such as caching plugins or server‑side caches, so that any stored malicious content is purged from the delivery layer and does not continue to serve users.

Generated by OpenCVE AI on September 2, 2026 at 05:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Elegant Themes
Elegant Themes divi
Wordpress
Wordpress wordpress
Vendors & Products Elegant Themes
Elegant Themes divi
Wordpress
Wordpress wordpress

Wed, 02 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Description The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Dynamic Content feature's legacy JSON format in all versions up to, and including, 4.27.6. This is due to two compounding flaws: (1) the save-time sanitization filter `et_builder_sanitize_dynamic_content_fields()` only searches for dynamic content markers in the `@ET-DC@...@` format, but the rendering engine also supports a legacy JSON format that is silently converted at render time, completely bypassing the save-time filter, and (2) the `post_meta_key` resolver in `et_builder_filter_resolve_default_dynamic_content()` does not apply `wp_kses_post()` to the resolved meta value when `enable_html` is set to `on`, passing raw `get_post_meta()` output directly to the page. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Divi <= 4.27.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Dynamic Content (Legacy JSON Format) Shortcode
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Elegant Themes Divi
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-02T03:38:32.146Z

Reserved: 2026-03-09T20:07:38.681Z

Link: CVE-2026-3851

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-02T04:17:52.860

Modified: 2026-09-02T04:17:52.860

Link: CVE-2026-3851

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T05:30:08Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')