Junglewise Threat Intelligence

CVE-2026-5523: Divi Engine Divi Form Builder account takeover via missing authorization

CVE-2026-5523 · Severity: high · CVSS 8.8 · Published 2026-07-09

Technologies: Divi Engine Divi Form Builder. Vendors: Divi Engine.

Executive brief

The Divi Form Builder plugin for WordPress, which allows site owners to create custom contact and registration forms, contains a security flaw that allows unauthorized users to take over other accounts. By exploiting this vulnerability, a person with a basic user account can change the email address and password of any other user, including site administrators. This could lead to a total loss of control over the website and exposure of sensitive customer data.

Technical details

The Divi Form Builder plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) and Missing Authorization flaw in versions up to 5.1.8. The root cause is located in the update_user() function, which accepts a user ID parameter from form submissions without verifying if the authenticated user has the necessary permissions to modify that specific account. Additionally, the handle_register_submission() function fails to validate permissions for the target user, only checking if a user is logged in. An authenticated attacker with subscriber-level permissions can exploit these flaws to change the email and password of any user, including administrators. A patch was released in version 5.1.9.

Affected products

  • Divi Engine Divi Form Builder up to, and including, 5.1.8

Timeline

  • 2026-05-24: patched: Security hardening released in version 5.1.9
  • 2026-07-09: disclosed: CVE published to NVD

References

Related threats