CVE-2026-15760: CWE-862 Missing Authorization in Divi Essential Divi Essentials
The Divi Essential WordPress plugin versions up to and including 5.8.1 contain an authorization bypass vulnerability. Authenticated users with Subscriber-level access or higher can exploit insufficient nonce verification in certain AJAX actions to enumerate database tables and read sensitive data, including user credentials and privileged settings. This vulnerability is tracked as CVE-2026-15760 and has a CVSS score of 6.5 (medium severity).
AI Analysis
Technical Summary
CVE-2026-15760 is a missing authorization vulnerability (CWE-862) in the Divi Essential WordPress plugin (up to version 5.8.1). The vulnerability arises because the AJAX handlers for dnxte_get_database_tables and dnxte_get_database_data only conditionally verify a nonce when the 'nonce' POST parameter is present, which can be bypassed by omitting the parameter. Additionally, the handlers do not enforce capability checks via current_user_can() or similar mechanisms. As a result, authenticated users with Subscriber-level privileges or higher can enumerate all WordPress database tables and read a caller-controlled number of rows from any table, including sensitive tables such as wp_users, wp_usermeta, and wp_options, exposing usernames, emails, hashed passwords, session tokens, secret keys, API keys, and other privileged data.
Potential Impact
An attacker with low-level authenticated access can access sensitive information stored in the WordPress database, including user credentials and secret keys. This exposure can lead to further compromise of the WordPress site or associated systems. The vulnerability does not affect unauthenticated users and does not allow modification or denial of service, but the confidentiality impact is high.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict user roles to trusted users only and monitor for suspicious activity. Avoid granting Subscriber-level or higher access to untrusted users. Follow vendor updates closely for a patch release.
CVE-2026-15760: CWE-862 Missing Authorization in Divi Essential Divi Essentials
Description
The Divi Essential WordPress plugin versions up to and including 5.8.1 contain an authorization bypass vulnerability. Authenticated users with Subscriber-level access or higher can exploit insufficient nonce verification in certain AJAX actions to enumerate database tables and read sensitive data, including user credentials and privileged settings. This vulnerability is tracked as CVE-2026-15760 and has a CVSS score of 6.5 (medium severity).
CVSS v3.1
Score 6.5medium
Affected software
Divi Essential
Divi Essentials
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-15760 is a missing authorization vulnerability (CWE-862) in the Divi Essential WordPress plugin (up to version 5.8.1). The vulnerability arises because the AJAX handlers for dnxte_get_database_tables and dnxte_get_database_data only conditionally verify a nonce when the 'nonce' POST parameter is present, which can be bypassed by omitting the parameter. Additionally, the handlers do not enforce capability checks via current_user_can() or similar mechanisms. As a result, authenticated users with Subscriber-level privileges or higher can enumerate all WordPress database tables and read a caller-controlled number of rows from any table, including sensitive tables such as wp_users, wp_usermeta, and wp_options, exposing usernames, emails, hashed passwords, session tokens, secret keys, API keys, and other privileged data.
Potential Impact
An attacker with low-level authenticated access can access sensitive information stored in the WordPress database, including user credentials and secret keys. This exposure can lead to further compromise of the WordPress site or associated systems. The vulnerability does not affect unauthenticated users and does not allow modification or denial of service, but the confidentiality impact is high.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict user roles to trusted users only and monitor for suspicious activity. Avoid granting Subscriber-level or higher access to untrusted users. Follow vendor updates closely for a patch release.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-07-14T17:23:31.755Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aadf7a955bf5e2cf501d543
Added to database: 09/19/2026, 02:47:05 UTC
Last enriched: 09/19/2026, 03:02:12 UTC
Last updated: 09/19/2026, 03:15:37 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.