SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-3850

MEDIUM · CVSS 6.4 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) through the `redirect_url` parameter in the `et_pb_contact_form` shortcode, affecting all versions up to 4.27.6. This flaw allows authenticated attackers with Contributor-level access or higher to inject malicious scripts that execute when users submit the contact form, potentially compromising user data and site integrity. WordPress site administrators using the Divi theme should prioritize patching this vulnerability to mitigate the risk of exploitation.

CVE
CVE-2026-3850
Severity
MEDIUM
CVSS
6.4
EPSS
0.16%
WordPress Java

Original NVD Description

The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `redirect_url` parameter of the `et_pb_contact_form` shortcode in all versions up to, and including, 4.27.6. This is due to the `redirect_url` attribute being sanitized with `esc_attr()` instead of `esc_url()` before being rendered into the `data-redirect_url` HTML data attribute. Additionally, `redirect_url` is absent from the hardcoded `$url_options` array in `class-et-builder-element.php`, so it does not receive `esc_url_raw()` sanitization during shortcode parsing. After a successful form submission, client-side JavaScript reads this data attribute and passes it directly to `window.location.href`, executing arbitrary JavaScript from a `javascript:` URI. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that execute whenever a user submits the contact form.