CVE-2020-35945

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
01/01/2021
Last modified:
12/01/2021

Description

An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:elegant_themes:divi:*:*:*:*:*:wordpress:*:* 3.0 (including) 4.5.3 (excluding)
cpe:2.3:a:elegant_themes:divi_builder:*:*:*:*:*:wordpress:*:* 2.0 (including) 4.5.3 (excluding)
cpe:2.3:a:elegant_themes:divi_extra:*:*:*:*:*:wordpress:*:* 2.0 (including) 4.5.3 (excluding)