Description
WordPress Plugin Divi Builder is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently manipulate posts. WordPress Plugin Divi Builder version 1.2.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.2.4 or latest
References
http://www.pritect.net/blog/elegant-themes-security-vulnerability
http://wptavern.com/critical-security-vulnerability-discovered-in-elegant-themes-products
http://us7.campaign-archive2.com/?u=9ae7aa91c578052b052b864d6&id=85b5d27651
Related Vulnerabilities
MySQL Resource Management Errors Vulnerability (CVE-2010-3833)
b2evolution Credentials Management Errors Vulnerability (CVE-2016-9479)
MySQL CVE-2022-21486 Vulnerability (CVE-2022-21486)
ZenCart Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2017-11675)
WordPress Plugin wp Dreamwork Gallery Arbitrary File Upload (2.3)