WordPress Plugin Vulnerabilities

ElegantThemes (Divi, Extra, divi-builder) - Authenticated Stored Cross-Site Scripting (XSS)

Description

A privilege escalation vulnerability was discovered that could allow low level users, such as Authors, to use unfiltered HTML inside of post content when using the Divi Builder. Using such code in posts is typically reserved for admins.

Affects Plugins

Fixed in 2.17.3

Affects Themes

Fixed in 3.17.3
Fixed in 2.17.3
Fixed in 3.17.3

References

Classification

Type
XSS
CWE

Miscellaneous

Submitter
Ryan Dewhurst
Submitter twitter
Verified
No

Timeline

Publicly Published
2018-10-30 (about 7 years ago)
Added
2018-10-31 (about 7 years ago)
Last Updated
2020-11-26 (about 5 years ago)

Other