Ghostwire

CVE-2026-13712: The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow module settings before...

CRITICAL CVSS 0.0

Published: August 16, 2026 | Last Modified: August 16, 2026

Description

The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow module settings before outputting them in link attributes, allowing users with a role as low as contributor to store JavaScript which will run when a higher privileged user, such as an administrator, views the post.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References