Junglewise Threat Intelligence

CVE-2026-15760: Divi Essential missing authorization in AJAX handlers

CVE-2026-15760 · Severity: medium · CVSS 6.5 · Published 2026-09-19

Executive brief

The Divi Essential plugin for WordPress allows authenticated users with low-level (Subscriber) access to bypass security checks in two AJAX handlers and query the site's entire database. An attacker can enumerate all database tables and read sensitive data including usernames, password hashes, session tokens, and API credentials stored by the WordPress installation or other plugins.

Technical details

The dnxte_get_database_tables and dnxte_get_database_data AJAX actions in Divi Essential up to 5.8.1 perform only conditional nonce verification (bypassed by omitting the nonce parameter) and lack capability checks via current_user_can(). Authenticated attackers with Subscriber+ privileges can exploit this to read arbitrary rows from any database table, including wp_users, wp_usermeta, and wp_options, exposing authentication material and plugin secrets.

Affected products

  • Divi Next Divi Essential up to and including 5.8.1

Timeline

  • 2026-09-19: disclosed: CVE-2026-15760 published

References