PT-2026-24587 · Undefined · Undefined

Saif

·

Published

2026-03-11

·

Updated

2026-03-15

·

CVE-2026-2626

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions divi-booster WordPress plugin versions prior to 5.0.2
Description The divi-booster WordPress plugin does not have authorization and Cross-Site Request Forgery (CSRF) checks in a specific function. This allows unauthenticated users to modify stored plugin options. The use of the unserialize() function on the data introduces a potential for PHP Object Injection when combined with a PHP gadget chain.
Recommendations Update the divi-booster WordPress plugin to version 5.0.2 or later.

Exploit

Fix

CSRF

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2026-2626

Affected Products

Undefined