CyberRota Analysis
AI-GeneratedThe Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient sanitization of dynamic content, allowing authenticated attackers with Contributor-level access or higher to inject malicious scripts. This vulnerability can lead to the execution of arbitrary web scripts on affected pages, posing a risk to users who access these pages. WordPress site administrators using the Divi theme should prioritize patching this vulnerability to protect their sites and users from potential exploitation.
Original NVD Description
The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Dynamic Content feature's legacy JSON format in all versions up to, and including, 4.27.6. This is due to two compounding flaws: (1) the save-time sanitization filter `et_builder_sanitize_dynamic_content_fields()` only searches for dynamic content markers in the `@ET-DC@...@` format, but the rendering engine also supports a legacy JSON format that is silently converted at render time, completely bypassing the save-time filter, and (2) the `post_meta_key` resolver in `et_builder_filter_resolve_default_dynamic_content()` does not apply `wp_kses_post()` to the resolved meta value when `enable_html` is set to `on`, passing raw `get_post_meta()` output directly to the page. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.