PT-2024-31295 · Elegant Themes · Divi+2

Craig Smith

+1

·

Published

2024-05-10

·

Updated

2024-05-14

·

CVE-2024-4490

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Elegant Themes Divi theme versions up to 4.25.0 Elegant Themes Extra theme versions up to 4.25.0 Divi Page Builder plugin for WordPress versions up to 4.25.0
Description The issue is related to DOM-Based Stored Cross-Site Scripting due to insufficient input sanitization and output escaping. This allows authenticated attackers with contributor-level permissions and above to inject arbitrary web scripts in pages via the title parameter. The injected scripts will execute whenever a user accesses the injected page.
Recommendations For Elegant Themes Divi theme versions up to 4.25.0, update to a version later than 4.25.0 to resolve the issue. For Elegant Themes Extra theme versions up to 4.25.0, update to a version later than 4.25.0 to resolve the issue. For Divi Page Builder plugin for WordPress versions up to 4.25.0, update to a version later than 4.25.0 to resolve the issue. As a temporary workaround, consider restricting access to the title parameter to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-4490

Affected Products

Divi
Divi Page Builder
Extra