← Back to browse · API

CVE-2020-35945

Severity
CRITICAL
CVSS
9.9
EPSS
0.02422
Risk score
40.45
CISA KEV
No
PoC
No
Published
2021-01-01
Modified
2024-08-04
First seen
2026-08-07
Aliases
EUVD-2020-23528, GHSA-V452-696F-F255
Products
n/a:n/a n/a
Sources
euvd EUVD-2020-23528

Description

An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side.

References