CVE-2020-35945
An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side.
- Affected products
- Divi Builder, Divi Extra Theme, Divi Theme
- Elegantthemes Divi
- < 4.5.3
- Elegantthemes Divi Builder
- < 4.5.3
- Elegantthemes Extra
- < 4.5.3
- Fix
- Available
- CVSS 3.1
- 9.9 CRITICAL
- EPSS
- 2.4% (83th percentile)
- Weakness
- CWE-434
- NVD status
- Analyzed
- Published
- 2021-01-01
CVE-2020-35945 at NVD
1 known exploit for CVE-2020-35945
Proof-of-concept code and exploit modules indexed by Sploitus