CVE-2026-4361: Divi <= 4.27.6 - Authenticated (Contributor+) Server-Side Request Forgery via 'image_src' Parameter

Published Sep 5, 2026
·
Updated

The Divi theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.27.6. This is due to the etpbsetvideooembedthumbnailresolution() function using wpremoteget() instead of wpsaferemoteget() to fetch a remote image URL, which does not restrict requests to private or reserved IP ranges. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application server. The response body is not returned to the attacker (blind SSRF), but two oracles exist: a status oracle (the returned URL string differs depending on whether the target responded with HTTP 200) and a timing oracle (response time varies by target reachability).

Affected Software

1 affected component
WordPress Divi theme<=4.27.6

Event History

Sep 5, 2026
CVE Published
via MITRE·06:37 AM
Data Sourced
via MITRE·06:37 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue in a WordPress site?

An attacker needs an authenticated WordPress account with at least the Contributor role. Unauthenticated visitors are not described as able to exploit it.

2

What can an attacker learn or do through the SSRF?

The attacker can cause the web application server to make requests to arbitrary locations, including private or reserved IP ranges. The response body is not exposed, but HTTP 200-dependent behavior and response timing can reveal whether a target is reachable or responding.

3

Which Divi versions are affected?

All Divi versions through 4.27.6, inclusive, are affected. The referenced Divi changelog identifies version 4.27.7.

4

How can defenders limit exposure before updating?

Restrict Contributor-level and higher accounts to trusted users, since those roles can trigger the vulnerable request path. Review such accounts for unauthorized access and limit the application server's ability to reach internal, private, and reserved network destinations where possible.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203