• Advertise
  • Cpanel Login
  • Privacy Policy
  • Webmail Login
ENDINOV blog
No Result
View All Result
Friday, March 5, 2021
  • Home
  • Categories
    • Domain Name
    • Glossary
    • News
    • Reviews
    • Security
    • Seo
    • Startup
    • Tutorials
    • Web Hosting
    • Websites
    • WordPress
  • Contact Us
Back Endinov webhost
Client Area
ENDINOV blog
  • Home
  • Categories
    • Domain Name
    • Glossary
    • News
    • Reviews
    • Security
    • Seo
    • Startup
    • Tutorials
    • Web Hosting
    • Websites
    • WordPress
  • Contact Us
No Result
View All Result
Endinov blog
No Result
View All Result
Home Websites WordPress

Significant flaw Over 700,000 sites are revealed using Divi, Extra, and Divi Builder

by Derrick
August 4, 2020 - Updated on August 7, 2020
in Security, WordPress
0
divi
383
SHARES
1.1k
VIEWS
Share on FacebookShare on TwitterShare on WhatsAppShare on LinkedIn

On July 23, 2020, wordfence Security Analysis team discovered a flaw present in two themes through Elegant Themes, Divi and Extra, as well as a WordPress plugin named Divi Creator. These products, combined, are installed at an estimated 700,000 sites.

This vulnerability provided authenticated attackers the ability to upload arbitrary files like PHP files, with contributor-level or above functionality, and achieve remote execution of code on the server of a compromised site.

RelatedPosts

So What Does An SSL Certificate Actually Do for You?

The Padlock or Bar You See On Your Web Browser (Part 1)

The developers replied on June 29, 2020 that the next version would have a patch coming in. Patches for both products is released August 3, 2020 in version 4.5.3.

This is considered a crucial security problem, and may lead to the execution of remote code on the server of a compromised location. Whether you have not downloaded and run Divi versions 3.0 and above, Extra versions 2.0 and above, or Divi Builder versions 2.0 and above, we highly suggest that you upgrade to the modified edition, 4.5.3, immediately. Alternatively, before you can upgrade securely you should use their Protection Patcher feature.

Description: Authenticated Arbitrary File Upload
Affected Products: Divi Theme, Extra Theme, and Divi Builder plugin
Theme Slugs: divi, extra
Plugin slug: divi-builder
Affected Versions: (Divi): 3.0 – 4.5.2
Affected Versions: (Extra): 2.0 – 4.5.2
Affected Versions: (Divi Builder): 2.0 – 4.5.2
CVE ID: Pending.
CVSS Score: 9.9 (CRITICAL)
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Fully Patched Version (same for all products): 4.5.3

The developer of one of the most famous premium themes, Divi, is Elegant Themes. One of the advantages of the Divi theme is that it comes with the Divi Page Builder which makes it simple and customisable to design and update the site. Apart from the Divi theme, Elegant Themes often provides an additional style, Extra, which contains the Divi Creator. Also available is the standalone Divi Builder plugin, that can be used with any theme.

Users with the ability to create posts will import and export Divi-page templates utilizing the portability feature as part of the Divi Creator features.

It was found that while this function used a verification test of the form of file on the client side, it omitted a verification test on the server side. This vulnerability allowed authenticated attackers to quickly circumvent the client-side checkup of JavaScript and upload malicious PHP files to a given website. An intruder might potentially use a malware file posted via this process to take control of the website entirely.

ADVERTISEMENT

As long as you have provided user name and API key to your elegant themes on your WordPress platform, you can directly take charge of your updates in your updates field. Sign in to your account to do so, and navigate to the “Updates” page. Pick the product you wish to upgrade on Elegant Themes and simply click on “Update Button” or “update Theme” based on the product you are updating.

Additionally , please notice that this fix has been made accessible to users through Elegant Themes, even though your account is inactive.

Tags: pluginssecuritythemesvulnerability
ADVERTISEMENT
Previous Post

Accessing DNS Management Area

Next Post

WordPress.com is launching a new P2 tool for internal operations

Related Posts

WordPress version 5.5 released: A major update.
News

WordPress version 5.5 released: A major update.

by Derrick
August 13, 2020
0
1.1k

This new version contains a lot of improvements, many focusing on the WordPress block editor. This also contains long-awaited features...

Read more
p2

WordPress.com is launching a new P2 tool for internal operations

August 7, 2020
1.1k
So What Does An SSL Certificate Actually Do for You?

So What Does An SSL Certificate Actually Do for You?

June 25, 2020
1.1k
Next Post
p2

WordPress.com is launching a new P2 tool for internal operations

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Trending
  • Comments
  • Latest
web

Giving your developer access without sharing your own passwords

August 4, 2020
What Is A Domain Name?

What Is A Domain Name?

June 14, 2020
Domain Name, The Address You Enter To Visit A Website.

Domain Name, The Address You Enter To Visit A Website.

June 14, 2020
Using MySQL in a Hosting Environment

Using MySQL in a Hosting Environment

June 14, 2020
Web Hosting. What is it?

Web Hosting. What is it?

0
What Is A Domain Name?

What Is A Domain Name?

0
Domain Name, The Address You Enter To Visit A Website.

Domain Name, The Address You Enter To Visit A Website.

0
Web Server Hosting Types

Web Server Hosting Types

0
WordPress version 5.5 released: A major update.

WordPress version 5.5 released: A major update.

August 13, 2020
p2

WordPress.com is launching a new P2 tool for internal operations

August 7, 2020
divi

Significant flaw Over 700,000 sites are revealed using Divi, Extra, and Divi Builder

August 4, 2020 - Updated on August 7, 2020
dns

Accessing DNS Management Area

August 4, 2020
Facebook Twitter Instagram LinkedIn

#3
Adasa Street
East Legon, Accra

Phone: (233) 030 3971 615
Mail: contact@endinov.com

Categories

  • Domain Name
  • Glossary
  • News
  • Security
  • Tutorials
  • Web Hosting
  • Websites
  • WordPress

Newsletter

© 2020 Endinov Web Host.

No Result
View All Result
  • Home
  • Categories
    • Domain Name
    • Glossary
    • News
    • Reviews
    • Security
    • Seo
    • Startup
    • Tutorials
    • Web Hosting
    • Websites
    • WordPress
  • Contact Us
  • Other
    • Back To Endinov
    • Advertise
    • Cpanel Login
    • Webmail Login
    • Privacy Policy
  • Login

© 2020 Endinov Web Host.

Login to your account below

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In