PatchSiren

Elegant Themes CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Elegant Themes CVE published 2026-09-02

CVE-2026-3851

The Divi theme for WordPress, specifically versions up to and including 4.27.6, is vulnerable to Stored Cross-Site Scripting (XSS) attacks through its Dynamic Content feature's legacy JSON format. This vulnerability arises from two primary issues: (1) the save-time sanitization filter `et_builder_sanitize_dynamic_content_fields()` only checks for dynamic content markers in the `@ET-DC@...@` format, but th [truncated]