CVE-2026-14321
Gravedad CVSS v3.1:
ALTA
Tipo:
CWE-400
Consumo de recursos no controlado (Agotamiento de recursos)
Fecha de publicación:
23/09/2026
Última modificación:
23/09/2026
Descripción
*** Pendiente de traducción *** The divi-dash WordPress plugin before 1.0.7 does not validate the source of the client IP address it uses for rate limiting and banning, allowing unauthenticated attackers to spoof arbitrary IP addresses in order to bypass rate limiting, ban chosen addresses from the feature, and grow a stored option without bound, resulting in denial of service.
Impacto
Puntuación base 3.x
8.20
Gravedad 3.x
ALTA


