The divi-booster WordPress plugin before 5.0.2 does not have authorization and CSRF checks in one of its fixing function, allowing unauthenticated users to modify stored divi-booster WordPress plugin before 5.0.2 options. Furthermore, due to the use of unserialize() on the data, this could be further exploited when combined with a PHP gadget chain to achieve PHP Object Injection
CVE-2026-2626
NONE
EPSS 0.03%
Updated Mar 11, 2026
WordPress
CVE Details
CVE ID
CVE-2026-2626
Published Date
Mar 11, 2026
Vendor
WordPress
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.03%
Likelihood of exploitation in next 30 days
Percentile:
7.2th percentile (higher than 7.2% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory