Divi Form Builder Missing Authorization Vulnerability Allowing Privilege Escalation

Vulnerability

A vulnerability exists in the Divi Form Builder plugin for WordPress, in versions through 5.1.8, allowing for unauthorized changes to user accounts. The issue arises because the update_user() function accepts user ID parameters from form submissions without proper authorization checks. As a result, authenticated attackers with subscriber-level access or higher can modify the email addresses and passwords of any user, including administrators, leading to complete account takeover.

Impact

Exploitation of this vulnerability allows for unauthorized users to change the email addresses and passwords of any user account, including those of administrators, resulting in full account access.

Remediation

Users are advised to update the Divi Form Builder plugin to version 5.1.9 or a newer patched version.

Added: Jul 9, 2026, 6:24 AM
Updated: Jul 9, 2026, 6:24 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
0.0
relevance
9.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.