Description
The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `skype_url` shortcode attribute of the Social Media Follow module in all versions up to, and including, 4.27.6. This is due to a three-part sanitization failure: (1) the `skype_url` field is not included in the `$url_options` whitelist in `class-et-builder-element.php`, so it never invokes `esc_url_raw()` during shortcode processing, (2) the render code in `SocialMediaFollowItem.php` explicitly skips `esc_url()` for Skype URLs (`! $is_skype ? esc_url( $url ) : $skype_url`), and (3) only `sanitize_text_field()` is applied, which preserves single and double quote characters allowing attribute breakout. The unsanitized value is interpolated directly into a single-quoted `href` attribute (`href='{$social_network_link_url}'`). This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user interacts with the injected element.
Published: 2026-09-03
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Divi theme for WordPress contains a stored cross‑site scripting vulnerability in the Social Media Follow module. The skype_url shortcode attribute is not properly sanitized and is inserted directly into a link’s href attribute, allowing an attacker with Contributor or higher privileges to inject arbitrary JavaScript. A successful exploit would cause that script to execute in every user’s browser when the link is rendered, providing an attacker with the ability to steal session cookies, deface content, or perform other client‑side attacks. This flaw is catalogued as CWE‑79.

Affected Systems

The vulnerability affects Elegant Themes’ Divi theme for WordPress, all releases up to and including version 4.27.6. Users running 4.27.6 or older should review their installation and plan for an upgrade to 4.27.7 or newer.

Risk and Exploitability

With a CVSS score of 6.4 the vulnerability is considered medium severity; the EPSS score is not available and it is not listed in CISA’s KEV catalog. Attackers need authenticated Contributor+ access to the WordPress backend and must edit the Social Media Follow shortcode to supply a malicious skype_url. After injection, the payload will run in the context of the site whenever the link is accessed by any visitor. Because it relies on user privileges to inject the payload, an initial compromise or privilege escalation is required before the XSS can be deployed.

Generated by OpenCVE AI on September 3, 2026 at 12:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Divi theme to the latest version (4.27.7 or newer).
  • If an update cannot be performed immediately, remove or replace any Skype URL values in the Social Media Follow module or forcibly sanitize them to eliminate quotes and ensure proper escaping.
  • Disable or restrict Contributor+ access to the Social Media Follow module, limiting the ability to edit shortcode attributes.

Generated by OpenCVE AI on September 3, 2026 at 12:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Elegant Themes
Elegant Themes divi
Wordpress
Wordpress wordpress
Vendors & Products Elegant Themes
Elegant Themes divi
Wordpress
Wordpress wordpress

Thu, 03 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Description The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `skype_url` shortcode attribute of the Social Media Follow module in all versions up to, and including, 4.27.6. This is due to a three-part sanitization failure: (1) the `skype_url` field is not included in the `$url_options` whitelist in `class-et-builder-element.php`, so it never invokes `esc_url_raw()` during shortcode processing, (2) the render code in `SocialMediaFollowItem.php` explicitly skips `esc_url()` for Skype URLs (`! $is_skype ? esc_url( $url ) : $skype_url`), and (3) only `sanitize_text_field()` is applied, which preserves single and double quote characters allowing attribute breakout. The unsanitized value is interpolated directly into a single-quoted `href` attribute (`href='{$social_network_link_url}'`). This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user interacts with the injected element.
Title Divi <= 4.27.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Social Media Follow 'skype_url' Shortcode Parameter
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Elegant Themes Divi
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-03T13:16:54.004Z

Reserved: 2026-03-09T20:10:17.984Z

Link: CVE-2026-3852

cve-icon Vulnrichment

Updated: 2026-09-03T13:15:00.816Z

cve-icon NVD

Status : Deferred

Published: 2026-09-03T13:05:38.903

Modified: 2026-09-03T17:25:25.113

Link: CVE-2026-3852

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T12:30:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')