Junglewise Threat Intelligence

CVE-2026-4275: badhonrocks Divi Torque Lite CSRF in plugin installation endpoints

CVE-2026-4275 · Severity: high · CVSS 8.8 · Published 2026-07-09

Executive brief

The Divi Torque Lite plugin for WordPress, which provides additional modules for the Divi website builder, contains a security flaw that could allow an attacker to take control of a website. By tricking a logged-in administrator into clicking a malicious link, an attacker can remotely install and activate arbitrary plugins. This could lead to full site takeover, data theft, or the installation of malicious software on the server.

Technical details

The Divi Torque Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to an insecure REST API implementation in versions up to and including 4.2.3. The /install_plugin and /activate_plugin endpoints use '__return_true' as a permission_callback, which effectively bypasses WordPress's built-in REST API nonce verification. While the endpoint callbacks perform internal current_user_can() checks, these checks are satisfied by the session cookies of a logged-in administrator. An unauthenticated attacker can exploit this by inducing an administrator to visit a malicious URL, leading to the installation and activation of arbitrary plugins from the WordPress repository. A patch appears to be available in version 4.2.4 or via recent changesets.

Affected products

  • badhonrocks Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin <= 4.2.3

Timeline

  • 2026-07-09: disclosed
  • 2026-07-09: advisory

References