Themes Vulnerabilities

Divi 5.0 - 5.8.1 - Contributor+ Stored XSS via Social Media Follow Skype URL

Description

The theme does not properly escape some of its Social Media Follow module settings before outputting them in link attributes, allowing users with a role as low as contributor to store JavaScript which will run when a higher privileged user, such as an administrator, views the post.

Proof of Concept

Affects Themes

Fixed in 5.9.0

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
*,.$n.,*Sico.eX
Submitter
*,.$n.,*Sico.eX
Verified
Yes

Timeline

Publicly Published
2026-08-14 (about 2 days ago)
Added
2026-08-14 (about 1 day ago)
Last Updated
2026-08-14 (about 1 day ago)

Other