A serious security flaw, identified as CVE-2020-35945, was found in the popular Divi Builder plugin, Divi theme, and Divi Extra theme for WordPress. This critical vulnerability allowed unauthorized file uploads, potentially enabling attackers to take full control of affected websites.
CVE Details
This vulnerability affects the Divi ecosystem, which includes the Divi Builder plugin, Divi theme, and Divi Extra theme. It was publicly disclosed on January 1, 2021, and is classified with a critical severity level, boasting a CVSS score of 9.9. The status of this vulnerability is “Analyzed,” meaning it has been thoroughly investigated and confirmed.
Affected Products
The following Elegant Themes products for WordPress are impacted by this arbitrary file upload vulnerability:
- Elegant Themes Divi theme (all versions before 4.5.3)
- Elegant Themes Divi Builder plugin (all versions before 4.5.3)
- Elegant Themes Divi Extra theme (all versions before 4.5.3)
If you are using any version of these products prior to 4.5.3, your website is at significant risk.
Current Status
The vulnerability, CVE-2020-35945, has been fully analyzed. This indicates that its nature, impact, and potential exploitation methods are well-understood within the cybersecurity community. While the vulnerability is known, it does not mean the threat is gone. Affected systems remain vulnerable until patched.
Severity Level
Rated as CRITICAL with a CVSS score of 9.9, this vulnerability poses an extremely high risk. A critical rating means that exploiting this flaw could lead to severe consequences, such as complete system compromise, data theft, or website defacement. In this case, authenticated attackers with contributor-level access or higher could upload malicious PHP files, which could then be executed on the server, giving them extensive control over your WordPress site.
Possible Solutions
The most important step to protect your WordPress site from CVE-2020-35945 is to immediately update your Divi Builder plugin, Divi theme, and Divi Extra theme to version 4.5.3 or later. Elegant Themes released patches to address this flaw, and updating ensures you receive these crucial security fixes.
Beyond this specific fix, it’s always good practice to:
- Keep all your WordPress themes, plugins, and core installation updated to their latest versions.
- Limit user permissions to the lowest necessary level. For instance, only grant contributor or author roles to trusted individuals.
- Implement a robust security plugin like Wordfence to monitor for suspicious activity and provide an additional layer of protection.
- Perform regular backups of your website data.
References
https://wpscan.com/vulnerability/10342
https://www.wordfence.com/blog/2020/08/critical-vulnerability-exposes-over-700000-sites-using-divi-extra-and-divi-builder/


