← Vulnerability feed

Vulnerability record · CVE-2020-35945 · published 1 January 2021

CVE-2020-35945: Elegantthemes divi unrestricted file upload vulnerability

Elegantthemes · Divi

An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side.

8.8 CVSS 3.1 High EPSS 2.5% · top 16.2% CWE-434 · Unrestricted file upload
8.8CVSS 3.1 base score, v2 6.5
2.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-35945 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2016-11002Elegantthemes extra improper privilege management vulnerabilityThe Elegant Themes Extra theme before 1.2.4 for WordPress has privilege escalation.EPSS 1.9%5.4CVE-2024-5533Elegantthemes divi improper input validation vulnerabilityThe Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.25.1 due to insufficient input sani…EPSS 0.26%5.4CVE-2023-6744Elegantthemes divi cross-site scripting vulnerabilityThe Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'et_pb_text' shortcode in all versions up to, and includin…EPSS 0.33%5.4CVE-2023-29099Elegantthemes divi cross-site scripting vulnerabilityAuth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Elegant themes Divi theme <= 4.20.2 versions.EPSS 0.36%5.0CVE-2015-1579Elegantthemes divi path traversal vulnerabilityDirectory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) i…EPSS 21%10.0CVE-2026-56291Balbooa Forms Joomla extension unauthenticated arbitrary file upload RCEThe Balbooa Forms extension for Joomla before version 2.4.1 accepts file uploads without authentication and does not restrict file type, allowing exe…KEVEPSS 15%analysed10.0CVE-2026-48939iCagenda Joomla extension unrestricted file upload leads to PHP RCEThe iCagenda extension for Joomla fails to restrict file types in its file attachment feature, allowing arbitrary file uploads that result in PHP cod…KEVEPSS 20%analysed10.0CVE-2026-56290Joomla Page Builder CK unauthenticated file upload leads to RCEThe Joomla Page Builder CK extension before 3.6.0 allows unauthenticated arbitrary file uploads, letting an attacker place executable files on the se…KEVEPSS 31%analysed

Source: NIST National Vulnerability Database (record CVE-2020-35945), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.