CVE-2026-5118
The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2. This is due to the plugin accepting a user-controlled 'role' parameter from POST data during user registration without validating it against the form's configured default_user_role setting. This makes it possible for unauthenticated attackers to create administrator accounts by tampering with the role parameter during registration.
- Affected products
- Divi Form Builder
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 0.5% (40th percentile)
- Weakness
- CWE-269
- NVD status
- Deferred
- Published
- 2026-05-21
CVE-2026-5118 at NVD
5 known exploits for CVE-2026-5118
Proof-of-concept code and exploit modules indexed by Sploitus