Divi Booster WordPress Plugin Unauthenticated PHP Object Injection Vulnerability

Vulnerability

A vulnerability in the Divi Booster WordPress plugin, affecting versions prior to 5.0.2, allows unauthenticated users to modify plugin options. The issue arises from a lack of authorization and Cross-Site Request Forgery (CSRF) protections in a specific function. Additionally, the vulnerability can be exploited further by leveraging PHP object injection, due to the plugin's use of the unserialize() function on the data.

Impact

Exploitation of this vulnerability allows for unauthorized modification of plugin options and could lead to arbitrary PHP object injection, where an attacker can manipulate object deserialization to execute malicious code.

Reproduction

To reproduce this vulnerability, the Divi theme must be active, and the plugin settings should have been saved at least once to activate the plugin's fix. Once these conditions are met, an unauthenticated request can be sent to upload a crafted file that exploits the vulnerability. After the upload, the modified option can be verified in the WordPress options table.

Remediation

Users are advised to update the Divi Booster WordPress plugin to version 5.0.2 or later.

Added: Mar 11, 2026, 6:22 AM
Updated: Mar 11, 2026, 6:22 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.7
remediation
0.0
relevance
3.8
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.