CVE-2026-14321 PUBLISHED

Divi Dash < 1.0.7 - Unauthenticated Denial of Service via IP Address Spoofing

Assigner: WPScan
Reserved: 01.07.2026 Published: 23.09.2026 Updated: 23.09.2026

The divi-dash WordPress plugin before 1.0.7 does not validate the source of the client IP address it uses for rate limiting and banning, allowing unauthenticated attackers to spoof arbitrary IP addresses in order to bypass rate limiting, ban chosen addresses from the feature, and grow a stored option without bound, resulting in denial of service.

Product Status

Vendor Unknown
Product divi-dash
Versions Default: unaffected
  • affected from 0 to 1.0.7 (excl.)

Credits

  • Mike Gozdiskowski finder
  • WPScan coordinator

References

Problem Types

  • CWE-400 Uncontrolled Resource Consumption CWE