VYPR
Medium severity6.4NVD Advisory· Published Sep 2, 2026

CVE-2026-3851

CVE-2026-3851

Description

The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Dynamic Content feature's legacy JSON format in all versions up to, and including, 4.27.6. This is due to two compounding flaws: (1) the save-time sanitization filter et_builder_sanitize_dynamic_content_fields() only searches for dynamic content markers in the @ET-DC@...@ format, but the rendering engine also supports a legacy JSON format that is silently converted at render time, completely bypassing the save-time filter, and (2) the post_meta_key resolver in et_builder_filter_resolve_default_dynamic_content() does not apply wp_kses_post() to the resolved meta value when enable_html is set to on, passing raw get_post_meta() output directly to the page. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.