CVE-2026-13712 PUBLISHED

Divi 5.0 - 5.8.1 - Contributor+ Stored XSS via Social Media Follow Skype URL

Assigner: WPScan
Reserved: 29.06.2026 Published: 16.08.2026 Updated: 16.08.2026

The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow module settings before outputting them in link attributes, allowing users with a role as low as contributor to store JavaScript which will run when a higher privileged user, such as an administrator, views the post.

Product Status

Vendor Unknown
Product Divi
Versions Default: unaffected
  • affected from 5.0 to 5.9.0 (excl.)

Credits

  • * finder
  • .$n. finder
  • *Sico.eX finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE