Vulnerability Description
The Divi Form Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.1.8. This is due to the update_user() function accepting a user ID parameter from form submissions without verifying that the authenticated user has permission to edit that specific user account, and the handle_register_submission() function only checking if any user is logged in rather than validating permissions for the target user. This makes it possible for authenticated attackers, with subscriber-level access and above, to change the email address and password of any user account, including administrators, resulting in complete account takeover.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://diviengine.com/divi-form-builder-changelog/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/cb158acc-69d7-4a7d-b35
FAQ
What is CVE-2026-5523?
CVE-2026-5523 is a vulnerability with a CVSS score of 8.8 (HIGH). The Divi Form Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.1.8. This is due to the update_user() function accepting a user ID parameter from ...
How severe is CVE-2026-5523?
CVE-2026-5523 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-5523?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.