CVE-2026-5118

Divi · Divi Form Builder

The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation, allowing unauthenticated attackers to register as administrative users.

Executive summary

A critical privilege escalation vulnerability in the Divi Form Builder plugin for WordPress allows unauthenticated users to register as administrators.

Vulnerability

This is a privilege escalation flaw where the plugin fails to properly validate the 'role' parameter during user registration. Consequently, an unauthenticated attacker can manipulate this parameter to gain administrative privileges upon account creation.

Business impact

The CVSS score of 9.8 reflects the high severity of this vulnerability. Unauthorized administrative access allows attackers to gain full control over the WordPress installation, leading to data exfiltration, malicious content injection, and total site takeover, which can cause profound reputational and security damage.

Remediation

Immediate Action: Update the Divi Form Builder plugin to the latest version provided by the vendor.

Proactive Monitoring: Audit user accounts for any unauthorized administrator registrations or suspicious account activity initiated since the deployment of the plugin.

Compensating Controls: Temporarily disable user registration functionality on the WordPress site until the plugin has been updated and verified.

Exploitation status

Public Exploit Available: false

Analyst recommendation

This vulnerability represents a total loss of site integrity. Organizations using this plugin must prioritize updating to the latest version to prevent unauthorized administrative takeover and safeguard sensitive site data.