Vulnerabilities

Summary — last 7 days

New vulnerabilities2,616▼ 309 vs. last week
Critical / high1,342▲ 71 vs. last week
New active exploitation (KEV)5▼ 3 vs. last week
Unscored (no CVSS)62▼ 465 vs. last week
–

3 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (8.8)0.44%—Elegantthemes Divi Form BuilderAI7/9/20267/9/2026
The Divi Form Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.1.8. This is due to the update_user() function accepting a user ID parameter from form submissions without verifying that the authenticated user has permission to edit that specific user account, and…
DeferredCritical (9.8)3.5%—Divi Form BuilderAI7/2/20267/2/2026
The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and including 5.1.8. This is due to insufficient file extension validation in the do_image_upload() function where user-supplied input from the acceptFileTypes POST parameter is…
DeferredCritical (9.8)0.53%—Divi Form BuilderAI5/21/20267/23/2026
The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2. This is due to the plugin accepting a user-controlled 'role' parameter from POST data during user registration without validating it against the form's configured default_user_role setting. This…