CVE-2020-35945: Malicious File Upload
An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-35945?
CVE-2020-35945 is considered critical due to its potential to allow authenticated attackers to upload malicious files.
How do I fix CVE-2020-35945?
To fix CVE-2020-35945, update the Divi Builder, Divi theme, and Divi Extra theme to version 4.5.3 or later.
Who is affected by CVE-2020-35945?
WordPress installations using versions of the Divi Builder, Divi theme, and Divi Extra theme prior to 4.5.3 are affected by CVE-2020-35945.
What type of attacks can CVE-2020-35945 enable?
CVE-2020-35945 allows authenticated attackers with contributor-level access or higher to upload arbitrary PHP files to the server.
What is the exploitation impact of CVE-2020-35945?
Exploitation of CVE-2020-35945 can lead to remote code execution on affected WordPress sites.