๐Ÿ” CVE Alert

CVE-2026-13712

UNKNOWN 0.0

Divi 5.0 - 5.8.1 - Contributor+ Stored XSS via Social Media Follow Skype URL

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow module settings before outputting them in link attributes, allowing users with a role as low as contributor to store JavaScript which will run when a higher privileged user, such as an administrator, views the post.

Vendor unknown
Product divi
Published Aug 16, 2026
Stay Ahead of the Next One

Get instant alerts for unknown divi

Be the first to know when new unknown vulnerabilities affecting unknown divi are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Divi
5.0 < 5.9.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/d3a37071-5fb1-4aa2-8f89-eb13c46f6126/

Credits

* .$n. *Sico.eX WPScan