Medium 6.4
2025-07-03< 4.27.2
Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library
Minimum safe version
4.27.2
Update to 4.27.2 or later to address 7 fixable vulnerabilities
Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library
CVE-2024-4490
Elegant Themes (Various Versions) - Stored Cross-Site Scripting
Elegant Themes Divi 3.23 - 4.0.9, Divi Extra 2.23 - 4.0.9, Divi Builder 2.23 - 4.0.9 - PHP Code Injection
wpscan.com
WordPress Elegant Themes <= 2.6.3 - Privilege Escalation
WordPress Extra premium theme <= 4.0.9 - Authenticated Code Injection vulnerability
CVE-2016-11002
CVE-2020-35945