CVE-2026-14321: Divi Dash < 1.0.7 - Unauthenticated Denial of Service via IP Address Spoofing
The divi-dash WordPress plugin before 1.0.7 does not validate the source of the client IP address it uses for rate limiting and banning, allowing unauthenticated attackers to spoof arbitrary IP addresses in order to bypass rate limiting, ban chosen addresses from the feature, and grow a stored option without bound, resulting in denial of service.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker can exploit it remotely because the affected plugin trusts a client IP address value without validating its source.
What can an attacker do beyond bypassing rate limits?
An attacker can spoof arbitrary IP addresses to cause selected addresses to be banned from the feature. They can also grow a stored option without bound, which can lead to denial of service.
Which installations are affected?
Divi Dash versions before 1.0.7 are affected. The issue concerns the plugin's client-IP handling for rate limiting and banning.