CVE-2026-13712
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Aug 16, 2026
Vendor
unknown
Description
The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow module settings before outputting them in link attributes, allowing users with a role as low as contributor to store JavaScript which will run when a higher privileged user, such as an administrator, views the post.