Impact
The vulnerability permits attackers to trigger WordPress shortcodes without proper authorization. Improper validation of the content parameter in the Divi Shortcode Module REST endpoint causes the theme to run any supplied shortcode. When the optional "Force Enable D4 Shortcode Framework" setting is enabled, the attacker can also inject content that, for example, uses the et_pb_contact_form shortcode to send an email to an attacker‑chosen recipient. Consequently, an unauthenticated user can read or control any shortcode‑based functionality exposed by Divi.
Affected Systems
WordPress sites that use Elegant Themes Divi up to and including version 5.11.1. The defect exists in all releases before the 5.12.0 update.
Risk and Exploitability
The CVSS base score of 5.3 indicates a moderate severity. The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting a low likelihood of widespread exploitation at present. The REST endpoint is accessible without authentication, so any visitor can supply a malicious content value. Once the optional framework is enabled, the attack can lead to unsolicited email delivery or more widespread shortcode manipulation. Although exploitation probability is currently low, the presence of the feature flag and the lack of authentication create a non‑negligible risk for sites that have not applied the patch.
OpenCVE Enrichment