Sceawere

Vulnerability Detail

CVE-2026-39725UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Content Visibility RCE Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
16h ago
Vendor
Jonathan Horowitz
Product
Content Visibility for Divi Builder
Attack Type
CWE-94 Improper Control of Generation of Code ('Code Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Contributor Remote Code Execution (RCE) in Content Visibility for Divi Builder <= 5.03 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-10-06T09:17:44.683Z",
  "pubdate": "2026-10-06T09:17:44.683Z",
  "executiveSummary": "The Content Visibility for Divi Builder plugin, specifically versions 5.03 and below, is susceptible to a Remote Code Execution (RCE) vulnerability. This security flaw stems from insufficient input validation and improper handling of user-supplied data, allowing authenticated users with contributor-level privileges or higher to execute arbitrary code on the underlying server.\nThe vulnerability type is classified as Remote Code Execution, which represents a critical security risk. By successfully exploiting this flaw, an attacker can bypass existing security controls to gain unauthorized access to the application environment, potentially leading to full system compromise.\nImpacted systems include WordPress installations utilizing the Content Visibility for Divi Builder plugin within the affected version range. The risk implications are severe, as RCE allows for data exfiltration, modification of site content, deployment of backdoors, or the initiation of further attacks within the internal network.\nExploitation requires the attacker to possess at least Contributor-level access to the WordPress dashboard. The vulnerability is triggered by leveraging the plugin's internal functionality to process malicious input, which is then passed to server-side execution sinks without adequate sanitization or verification.",
  "technicalDetails": "The vulnerability exists due to insecure implementation of user-controlled parameters within the plugin’s processing logic. The core issue lies in the improper sanitization and validation of input before it is utilized in sensitive operations, likely involving the evaluation or dynamic execution of provided data strings.\nThe attack flow commences when an authenticated user with contributor privileges interacts with the plugin's configuration or utility functions that handle serialized or dynamic content objects. Because the plugin fails to enforce strict allow-lists or perform adequate context-aware encoding, an attacker can inject malicious payloads containing executable code fragments.\nSpecifically, the vulnerable component processes the submitted request and passes the tainted data to a downstream function capable of evaluating the input. In many PHP-based environments, this often involves improper use of functions such as 'eval()', 'call_user_func()', or other variants that facilitate dynamic code execution. When the application processes this payload, it inadvertently executes the attacker-supplied instructions with the permissions of the web server process (e.g., www-data).\nBecause the execution occurs server-side, the attacker is not limited by the client-side restrictions of the browser. Once the malicious code is executed, the attacker can leverage the server environment to perform various post-exploitation activities. These activities include, but are not limited to, unauthorized access to the database configuration, exfiltration of administrative credentials, installation of web shells for persistent access, and the execution of arbitrary system commands on the host operating system.\nThe vulnerability is restricted by an authentication requirement; however, since contributor-level accounts are often easily obtained via social engineering or low-privileged account takeover, the actual exposure is significant. The attack surface is directly tied to the plugin's interface exposed to contributors within the WordPress administrative panel. The lack of robust input validation mechanisms effectively allows for the elevation of privileges from a restricted contributor role to arbitrary code execution, bypassing the intended design of the Content Visibility framework."
}
CVE-2026-39725: Content Visibility RCE Vulnerability (HIGH Severity, CVSS: 8.8) | Sceawere