Security Advisory

CVE-2020-35945

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-01-01 03:28:27
Last updated 2024-08-04 17:16:13
Assigner mitre
CVSS score 9.9
State PUBLISHED

Description

An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side.