WordPress Plugin Vulnerabilities
Divi Dash < 1.0.7 - Unauthenticated Denial of Service via IP Address Spoofing
Description
The plugin does not validate the source of the client IP address it uses for rate limiting and banning, allowing unauthenticated attackers to spoof arbitrary IP addresses in order to bypass rate limiting, ban chosen addresses from the feature, and grow a stored option without bound, resulting in denial of service.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
Mike Gozdiskowski
Submitter
Mike Gozdiskowski
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-09-21 (about 2 days ago)
Added
2026-09-21 (about 1 day ago)
Last Updated
2026-09-21 (about 1 day ago)