Impact
The Divi Torque Lite plugin is vulnerable to a Cross‑Site Request Forgery (CWE‑352) flaw that allows an attacker to trigger the plugin’s /install_plugin REST endpoint from an authenticated administrator’s browser. Because the endpoint’s permission_callback always returns true and no nonce verification is performed, an attacker can bypass authentication checks and force the installation of any plugin from the WordPress repository. This flaw enables an attacker to install potentially malicious plugins without the administrator’s direct approval.
Affected Systems
All releases of the Divi Torque Lite – Divi Modules for Divi Builder & Theme plugin by badhonrocks up to and including version 4.2.3 are affected. Sites running any of those versions are at risk if their administrators are logged in and can be tricked into visiting a malicious page.
Risk and Exploitability
The CVSS score of 8.8 classifies the vulnerability as high severity. EPSS is reported as less than 1 %, indicating a low probability of exploitation, but the flaw can be leveraged if an attacker convinces a logged‑in administrator to load a malicious page—this inference is based on the description provided. The vulnerability is not currently listed in CISA’s KEV catalog. The attacker’s ability to install arbitrary plugins means that, if the plugin contains malicious code, the attacker can compromise the site’s integrity and confidentiality, and potentially cause denial of service. The flaw does not provide direct remote code execution without the plugin code used by the attacker.
OpenCVE Enrichment