Executive brief
The Content Visibility for Divi Builder plugin for WordPress, which allows site owners to control who sees specific page content, contains a critical security flaw. An attacker with basic contributor-level access can exploit this vulnerability to run unauthorized commands on the website's server. This could lead to a complete takeover of the site, theft of sensitive data, or the installation of malicious software.
Technical details
The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution (RCE) due to improper control of code generation (CWE-94). The flaw exists within the 'cvdb_content_visibility_check' parameter of the 'et_pb_text' shortcode. An authenticated attacker with at least Contributor-level privileges can inject and execute arbitrary PHP code on the underlying server. This vulnerability affects all versions of the plugin up to and including 4.02. A patch appears to be available in subsequent updates (changeset 3543621).
Affected products
- WordPress Plugin Content Visibility for Divi Builder up to, and including, 4.02
Timeline
- 2026-06-02: disclosed
- 2026-06-02: advisory
References
- https://plugins.trac.wordpress.org/browser/content-visibility-for-divi-builder/tags/4.01/includes/plugin.class.php
- https://plugins.trac.wordpress.org/changeset/3543621/content-visibility-for-divi-builder
- https://www.wordfence.com/threat-intel/vulnerabilities/id/2ea89c44-8ed0-4ab7-a049-4d1b03a898c7?source=cve