Elegantthemes
Products
6- 5 CVEs
- 2 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
Recent CVEs
9| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-35945 | Cri | 0.65 | 9.9 | 0.02 | Jan 1, 2021 | An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file… | ||
| CVE-2016-11004 | Hig | 0.57 | 8.8 | 0.02 | Sep 20, 2019 | The Elegant Themes Monarch plugin before 1.2.7 for WordPress has privilege escalation. | ||
| CVE-2016-11003 | Hig | 0.57 | 8.8 | 0.02 | Sep 20, 2019 | The Elegant Themes Bloom plugin before 1.1.1 for WordPress has privilege escalation. | ||
| CVE-2016-11002 | Hig | 0.57 | 8.8 | 0.02 | Sep 20, 2019 | The Elegant Themes Extra theme before 1.2.4 for WordPress has privilege escalation. | ||
| CVE-2025-0350 | Med | 0.42 | 6.4 | 0.00 | Jan 25, 2025 | The Divi Carousel Maker – Image, Logo, Testimonial, Post Carousel & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Carousel and Logo Carousel in all versions up to, and including, 2.0.4 due to insufficient input sanitization and… | ||
| CVE-2024-5533 | Med | 0.42 | 6.4 | 0.00 | Jun 18, 2024 | The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.25.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject… | ||
| CVE-2023-6744 | Med | 0.42 | 6.4 | 0.00 | Dec 23, 2023 | The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'et_pb_text' shortcode in all versions up to, and including, 4.23.1 due to insufficient input sanitization and output escaping on user supplied custom field data. This makes it possible… | ||
| CVE-2023-29099 | Med | 0.42 | 6.5 | 0.00 | Aug 8, 2023 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Elegant themes Divi theme <= 4.20.2 versions. | ||
| CVE-2015-1579 | 0.05 | — | 0.22 | Feb 11, 2015 | Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image action to wp-admin/admin-ajax.php. NOTE: this vulnerability may be a duplicate of… |
- risk 0.65cvss 9.9epss 0.02
An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file…
- risk 0.57cvss 8.8epss 0.02
The Elegant Themes Monarch plugin before 1.2.7 for WordPress has privilege escalation.
- risk 0.57cvss 8.8epss 0.02
The Elegant Themes Bloom plugin before 1.1.1 for WordPress has privilege escalation.
- risk 0.57cvss 8.8epss 0.02
The Elegant Themes Extra theme before 1.2.4 for WordPress has privilege escalation.
- risk 0.42cvss 6.4epss 0.00
The Divi Carousel Maker – Image, Logo, Testimonial, Post Carousel & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Carousel and Logo Carousel in all versions up to, and including, 2.0.4 due to insufficient input sanitization and…
- risk 0.42cvss 6.4epss 0.00
The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.25.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject…
- risk 0.42cvss 6.4epss 0.00
The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'et_pb_text' shortcode in all versions up to, and including, 4.23.1 due to insufficient input sanitization and output escaping on user supplied custom field data. This makes it possible…
- risk 0.42cvss 6.5epss 0.00
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Elegant themes Divi theme <= 4.20.2 versions.
- CVE-2015-1579Feb 11, 2015risk 0.05cvss —epss 0.22
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image action to wp-admin/admin-ajax.php. NOTE: this vulnerability may be a duplicate of…