Divi Engine Divi Form Builder
- <= 5.1.8
A vulnerability exists in the Divi Form Builder plugin for WordPress, in versions through 5.1.8, allowing for unauthorized changes to user accounts. The issue arises because the update_user() function accepts user ID parameters from form submissions without proper authorization checks. As a result, authenticated attackers with subscriber-level access or higher can modify the email addresses and passwords of any user, including administrators, leading to complete account takeover.
Exploitation of this vulnerability allows for unauthorized users to change the email addresses and passwords of any user account, including those of administrators, resulting in full account access.
Users are advised to update the Divi Form Builder plugin to version 5.1.9 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.