Medium 6.4
2025-07-03< 4.27.2
Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library
Minimum safe version
4.27.2
Update to 4.27.2 or later to address 9 fixable vulnerabilities
Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library
CVE-2024-5533
CVE-2024-4490
WordPress Divi Theme <= 4.23.1 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-29099
Elegant Themes (Various Versions) - Stored Cross-Site Scripting
Elegant Themes Divi 3.23 - 4.0.9, Divi Extra 2.23 - 4.0.9, Divi Builder 2.23 - 4.0.9 - PHP Code Injection
wpscan.com
WordPress Elegant Themes <= 2.6.3 - Privilege Escalation
WordPress Divi premium theme <= 4.0.9 - Authenticated Code Injection
CVE-2020-35945