CVE-2023-29099: WordPress Divi Theme <= 4.20.2 is vulnerable to Cross Site Scripting (XSS)
Published Aug 8, 2023
·Updated
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Elegant themes Divi theme <= 4.20.2 versions.
Affected Software
2 affected components
Elegant Themes Divi Wordpress<=4.20.2
Elegantthemes Divi Wordpress<=4.20.2
Remediation
Information
Update to 4.20.3 or a higher version.
Event History
Aug 8, 2023
CVE Published
via MITRE·10:45 AM
Data Sourced
via MITRE·10:45 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-29099?
CVE-2023-29099 has a high severity rating due to its stored Cross-Site Scripting (XSS) nature.
2
How do I fix CVE-2023-29099?
To fix CVE-2023-29099, update the Elegant Themes Divi theme to a version greater than 4.20.2.
3
What versions of Divi are affected by CVE-2023-29099?
CVE-2023-29099 affects Elegant Themes Divi theme versions up to and including 4.20.2.
4
Is being authenticated as a contributor sufficient to exploit CVE-2023-29099?
Yes, an authenticated user with contributor-level permissions can exploit CVE-2023-29099.
5
What type of vulnerability is CVE-2023-29099?
CVE-2023-29099 is classified as a stored Cross-Site Scripting (XSS) vulnerability.