WordPress Divi Theme Code Injection Vulnerability via @martinibuster - Website Pro USA
Website Builder,SEO,Social Media Consultant, Hosting, Website Care Plans
39304
post-template-default,single,single-post,postid-39304,single-format-standard,theme-bridge,woocommerce-no-js,ajax_updown,page_not_loaded,,qode-content-sidebar-responsive,columns-3,qode-child-theme-ver-1.0.0,qode-theme-ver-9.2,hide_inital_sticky,wpb-js-composer js-comp-ver-7.9,vc_responsive

WordPress Divi Theme Code Injection Vulnerability via @martinibuster

WordPress Divi Theme Code Injection Vulnerability via @martinibuster

ADVERTISEMENT

Elegant Themes announced that several of their products contained a code injection vulnerability and should be updated right away. The vulnerability allows an untrustworthy user to execute PHP functions.

Divi is a popular WordPress theme that is widely used around the world. It’s important that publishers update their theme and two other Elegant Themes products right away.

ADVERTISEMENT
CONTINUE READING BELOW

Elegant Themes Announcement

The official announcement detailed that the vulnerability was discovered during the course of a routine audit.

This is how they described the discovery:

“A code injection vulnerability was discovered by our team during a routine code audit that could allow logged in contributors, authors and editors to execute a small set of PHP functions.”

Elegant Themes Products with Vulnerability

Three products from Elegant Themes were discovered to contain a vulnerability. The products are the popular Divi theme, Extra theme and the Divi Builder plugin.

What is the Divi, Extra and Builder Vulnerability?

The vulnerability is a code injection variety. It allows contributors who are logged in to execute a limited set of PHP functions.

ADVERTISEMENT
CONTINUE READING BELOW

In general, a code injection attack allows a hacker to execute commands that can then compromise the website and sometimes even the entire server. In general, a code injection vulnerability can allow a malicious user to install malware on a website.

This vulnerability affects Elegant Theme publishers using Divi 3.23 and higher, Extra 2.23 and higher or Divi Builder 2.23 and higher who have granted publishing credentials to contributors.

How to Protect Against Divi Vulnerability

Updating to the latest versions of Divi, Extra and the Divi Builder plugin (versions 4.0.10) will protect you from this vulnerability.

While this vulnerability may not affect users who do not have third party contributors, authors and editors, it’s still worthwhile to update your Divi theme because there are numerous bug fixes that accompany this update.

No Comments

Sorry, the comment form is closed at this time.