What is CVE-2026-13712?
Divi WordPress theme versions before 5.9.0 do not properly escape some Social Media Follow module settings before outputting them in link attributes. This allows users with a role as low as contributor to store JavaScript that executes when a higher privileged user, such as an administrator, views the page.
Azərbaycanca: Divi WordPress temasının 5.9.0 versiyasından əvvəlki versiyalarında Social Media Follow modul parametrləri link atributlarında düzgün qaçırılmır (escape). Bu, contributor kimi aşağı səviyyəli istifadəçilərə JavaScript kodu yerləşdirməyə imkan verir ki, bu kod administrator kimi yüksək səlahiyyətli istifadəçi səhifəyə baxdıqda işə düşür.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What user role level can exploit CVE-2026-13712?
This vulnerability allows users with a role as low as contributor to store JavaScript code.
To which version should Divi theme be updated to avoid CVE-2026-13712?
You need to update the Divi WordPress theme to version 5.9.0 or higher, as the vulnerability affects versions before 5.9.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.