WordPress Plugin Vulnerabilities

Divi Booster < 5.0.2 - Unauthenticated PHP Object Injection

Description

The plugin does not have authorization and CSRF checks in one of its fixing function, allowing unauthenticated users to modify stored plugin options. Furthermore, due to the use of unserialize() on the data, this could be further exploited when combined with a PHP gadget chain to achieve PHP Object Injection

Proof of Concept

Affects Plugins

Fixed in 5.0.2

References

Classification

Type
OBJECT INJECTION
CWE
CVSS

Miscellaneous

Original Researcher
Saif (Team 51)
Submitter
Saif (Team 51)
Verified
Yes

Timeline

Publicly Published
2026-02-18 (about 21 days ago)
Added
2026-02-18 (about 21 days ago)
Last Updated
2026-02-18 (about 20 days ago)

Other