Impact
The Divi theme contains a stored cross‑site scripting flaw that allows authenticated users with Contributor access or higher to embed arbitrary JavaScript into page markup. The vulnerability arises from two flaws: a save‑time sanitizer that only checks for a specific dynamic content marker format, and a resolver that fails to apply proper output sanitization when legacy JSON formatted content is rendered. The affected code path results in the injected script executing whenever any site visitor loads the compromised page, thereby compromising the integrity and confidentiality of the site for end users.
Affected Systems
Elegant Themes Divi for WordPress, versions up through and including 4.27.6. All installs of this theme within that version range are susceptible, regardless of WordPress core or other plugins.
Risk and Exploitability
The overall CVSS score is 6.4, indicating a moderate impact. The EPSS score is unavailable, so the precise likelihood of exploitation in the wild cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed exploitation in the broader threat landscape yet. Attackers would need valid credentials that grant Contributor‑level editing rights to inject payloads via the Dynamic Content legacy JSON format. Once inserted, the payload persists across page loads until manually removed or the theme is upgraded.
OpenCVE Enrichment