PT-2026-24587 · Undefined · Undefined

Saif

·

Publicado

2026-03-11

·

Atualizado

2026-03-15

·

CVE-2026-2626

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions divi-booster WordPress plugin versions prior to 5.0.2
Description The divi-booster WordPress plugin does not have authorization and Cross-Site Request Forgery (CSRF) checks in a specific function. This allows unauthenticated users to modify stored plugin options. The use of the unserialize() function on the data introduces a potential for PHP Object Injection when combined with a PHP gadget chain.
Recommendations Update the divi-booster WordPress plugin to version 5.0.2 or later.

Exploit

Correção

CSRF

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-2626

Produtos afetados

Undefined