Software intelligence
Important: Divi Builder appearing in this catalog does not mean your website is affected. Exposure depends on your installed version. How SiteRespond intelligence works
Tracked advisories
6
Latest advisory
2 July 2025
CISA KEV matches
0
In this WordPress feed
WordPress slug
divi-builder
Plugin
This catalog lists 6 known advisories affecting Divi Builder. The most recent was published on 2 July 2025. If you use this software, compare your installed version against the affected ranges on each advisory and update to a fixed release outside those ranges. SiteRespond Defence checks your actual installed version when the plugin is connected — listing here does not by itself mean your site is vulnerable.
Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library
May allow attackers to run scripts in visitors' browsers or hijack admin sessions.
Published 2 July 2025
Elegant Themes Divi Theme, Extra Theme, Divi Page Builder <= 4.25.0 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
May allow attackers to run scripts in visitors' browsers or hijack admin sessions.
Published 9 May 2024
Elegant Themes (Multiple Versions) - Arbitrary File Upload
May allow attackers to run arbitrary code on the server if exploited.
Published 3 August 2020
Known Divi Builder advisories published by month.
CVE-2024-5647 · Published 2 July 2025
Affected versions: ≤ 4.27.1
CVE-2024-4490 · Published 9 May 2024
Affected versions: ≤ 4.25.0
CVE-2020-35945 · Published 3 August 2020
Affected versions: ≤ 4.3.2
No CVE assigned · Published 4 January 2020
Affected versions: ≥ 2.23 and ≤ 4.0.9
No CVE assigned · Published 30 October 2018
Affected versions: ≤ 2.17.2
CVE-2016-11004 · Published 17 February 2016
Affected versions: ≤ 1.2.3
SiteRespond Defence matches your installed Divi Builder version against this catalog when the Defence plugin is connected to your WordPress site.