Executive brief
The Divi Essential plugin for WordPress allows authenticated users with low-level (Subscriber) access to bypass security checks in two AJAX handlers and query the site's entire database. An attacker can enumerate all database tables and read sensitive data including usernames, password hashes, session tokens, and API credentials stored by the WordPress installation or other plugins.
Technical details
The dnxte_get_database_tables and dnxte_get_database_data AJAX actions in Divi Essential up to 5.8.1 perform only conditional nonce verification (bypassed by omitting the nonce parameter) and lack capability checks via current_user_can(). Authenticated attackers with Subscriber+ privileges can exploit this to read arbitrary rows from any database table, including wp_users, wp_usermeta, and wp_options, exposing authentication material and plugin secrets.
Affected products
- Divi Next Divi Essential up to and including 5.8.1
Timeline
- 2026-09-19: disclosed: CVE-2026-15760 published