Junglewise Threat Intelligence

CVE-2026-14321: divi-dash IP address spoofing in rate limiting

CVE-2026-14321 · Severity: high · CVSS 8.2 · Published 2026-09-23

Executive brief

The divi-dash WordPress plugin fails to validate the source of client IP addresses used in its rate limiting and banning feature. An attacker can spoof arbitrary IP addresses to bypass rate limits, ban legitimate users, and exhaust server storage, causing the site to become unresponsive or unavailable.

Technical details

The plugin improperly trusts user-supplied IP address data without validation, allowing unauthenticated attackers to inject arbitrary IPs for rate limiting decisions. By crafting requests with spoofed IP headers, attackers can bypass rate limits, block legitimate addresses, and trigger unbounded growth of stored options leading to denial of service. The vulnerability affects versions before 1.0.7 and requires no authentication or user interaction.

Affected products

  • divi-dash divi-dash before 1.0.7

Timeline

  • 2026-09-21: disclosed
  • 2026-09-21: patched: Fixed in version 1.0.7

References