CVE-2026-13712
Divi 5.0 - 5.8.1 - Contributor+ Stored XSS via Social Media Follow Skype URL
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow module settings before outputting them in link attributes, allowing users with a role as low as contributor to store JavaScript which will run when a higher privileged user, such as an administrator, views the post.
| Vendor | unknown |
| Product | divi |
| Published | Aug 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown divi
Be the first to know when new unknown vulnerabilities affecting unknown divi are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Divi
5.0 < 5.9.0
References
Credits
* .$n. *Sico.eX WPScan