VYPR

Divi Form Builder

by WordPress

CVEs (3)

  • CVE-2026-5118CriMay 21, 2026
    risk 0.64cvss 9.8epss 0.00

    The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2. This is due to the plugin accepting a user-controlled 'role' parameter from POST data during user registration without validating it against the form's…

  • CVE-2026-5523HigJul 9, 2026
    risk 0.00cvss 8.8epss 0.00

    The Divi Form Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.1.8. This is due to the update_user() function accepting a user ID parameter from form submissions without verifying that the authenticated user has permission…

  • CVE-2026-5524CriJul 2, 2026
    risk 0.00cvss 9.8epss 0.01

    The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and including 5.1.8. This is due to insufficient file extension validation in the do_image_upload() function where user-supplied input from…