The Divi theme for WordPress is vulnerable to Stored...
Moderate severity
Unreviewed
Published
Sep 2, 2026
to the GitHub Advisory Database
•
Updated Sep 2, 2026
Description
Published by the National Vulnerability Database
Sep 2, 2026
Published to the GitHub Advisory Database
Sep 2, 2026
Last updated
Sep 2, 2026
The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Dynamic Content feature's legacy JSON format in all versions up to, and including, 4.27.6. This is due to two compounding flaws: (1) the save-time sanitization filter
et_builder_sanitize_dynamic_content_fields()only searches for dynamic content markers in the@ET-DC@...@format, but the rendering engine also supports a legacy JSON format that is silently converted at render time, completely bypassing the save-time filter, and (2) thepost_meta_keyresolver inet_builder_filter_resolve_default_dynamic_content()does not applywp_kses_post()to the resolved meta value whenenable_htmlis set toon, passing rawget_post_meta()output directly to the page. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.References