Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 21 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 21 May 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2. This is due to the plugin accepting a user-controlled 'role' parameter from POST data during user registration without validating it against the form's configured default_user_role setting. This makes it possible for unauthenticated attackers to create administrator accounts by tampering with the role parameter during registration. | |
| Title | Divi Form Builder <= 5.1.2 - Unauthenticated Privilege Escalation via 'role' | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-05-21T14:16:06.460Z
Reserved: 2026-03-30T03:45:32.729Z
Link: CVE-2026-5118
Updated: 2026-05-21T14:16:01.280Z
Status : Deferred
Published: 2026-05-21T13:16:20.013
Modified: 2026-05-21T15:19:30.540
Link: CVE-2026-5118
No data.
OpenCVE Enrichment
Updated: 2026-05-21T13:30:11Z