CVE-2026-4275
The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.3. This is due to the use of '__return_true' as the permission_callback for the /install_plugin and /activate_plugin REST API endpoints, which bypasses WordPress's built-in REST API nonce verification. Although the endpoint callbacks contain internal current_user_can() checks, the absence of nonce verification means that a forged cross-site request from a logged-in administrator's browser will pass the capability check via the admin's session cookies. This makes it possible for unauthenticated attackers to install arbitrary plugins from WordPress.
Schwachstellenklasse
The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.3. This is due to the use of '__return_true' as the permission_callback for the /install_plugin and /activate_plugin REST API endpoints, which bypasses WordPress's built-in REST API nonce verification. Although the endpoint callbacks contain internal current_user_can() checks, the absence of nonce verification means that a forged cross-site request from a logged-in administrator's browser will pass the capability check via the admin's session cookies. This makes it possible for unauthenticated attackers to install arbitrary plugins from WordPress.
Quellen
- https://plugins.trac.wordpress.org/browser/addons-for-divi/tags/4.2.2/includes/rest-api.php#L230
- https://plugins.trac.wordpress.org/browser/addons-for-divi/tags/4.2.2/includes/rest-api.php#L75
- https://plugins.trac.wordpress.org/browser/addons-for-divi/tags/4.2.2/includes/rest-api.php#L81
- https://plugins.trac.wordpress.org/browser/addons-for-divi/trunk/includes/rest-api.php#L230
- https://plugins.trac.wordpress.org/browser/addons-for-divi/trunk/includes/rest-api.php#L75
- https://plugins.trac.wordpress.org/browser/addons-for-divi/trunk/includes/rest-api.php#L81
Finden Sie die Schwachstelle, bevor es ein Angreifer tut.
Melden Sie sich mit GitHub an und starten Sie Ihr erstes Audit in weniger als einer Minute. Für den kostenlosen Plan ist keine Kreditkarte nötig.