Skip to content

CVE-2026-5524 INCIBE-CERT - Vulnerabilities RSS / 22h The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and including 5.1.8. Attackers can specify PHP-executable extensions such as .phtml, .phar, .php5, or .php7 to bypass the plugin's .htaccess protection which only blocks .php files specifically.

www.incibe.es July 3, 2026

Puntuación base: 9.80 CRÍTICA Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vector de acceso (AV): A través de red Complejidad de acceso (AC): Bajo Privilegios Requeridos (PR): Ninguno Interacción del usuario (UI): Ninguno Alcance (S): Sin modificar Impacto a la confidencialidad (C): Alto Impacto a la integridad (I): Alto Impacto a la disponibilidad (A): Alto

Extracted Entities