CVE-2026-1829

The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.02 via the 'et_pb_text' shortcode 'cvdb_content_visibility_check' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.
Configurations

No configuration.

History

22 Jul 2026, 19:10

Type Values Removed Values Added
Summary
  • (es) El plugin Content Visibility for Divi Builder para WordPress es vulnerable a ejecución remota de código en todas las versiones hasta la 4.02, inclusive, a través del parámetro 'cvdb_content_visibility_check' del shortcode 'et_pb_text'. Esto permite a atacantes autenticados, con acceso de nivel Colaborador y superior, ejecutar código en el servidor.

02 Jun 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-02 20:16

Updated : 2026-07-22 19:10


NVD link : CVE-2026-1829

Mitre link : CVE-2026-1829

CVE.ORG link : CVE-2026-1829


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')