CVE-2026-2626

CVE-2026-2626: Divi Booster < 5.0.2 - Unauthenticated PHP Object Injection

Vendor Unknown
Product divi-booster
Published March 11, 2026
Last update March 11, 2026

CVSS base score

What the vulnerability does

01Description

The divi-booster WordPress plugin before 5.0.2 does not have authorization and CSRF checks in one of its fixing function, allowing unauthenticated users to modify stored divi-booster WordPress plugin before 5.0.2 options. Furthermore, due to the use of unserialize() on the data, this could be further exploited when combined with a PHP gadget chain to achieve PHP Object Injection

Explanation of Vulnerability in Simple Terms

02Summary

A vulnerability exists in Divi Booster versions before 5.0.2. The specific attack vector and impact cannot be determined from available metadata. Site administrators should update to version 5.0.2 or later immediately. Contact the vendor for detailed technical information about this issue.

What an attacker can do

03Attacker Capabilities

Unable to determine without CVSS vector and CWE classification.

Potential impact on your site

04Site Impact

Sites running Divi Booster below 5.0.2 may be at risk. Update to 5.0.2 or later.

Conditions required to exploit

05Prerequisites

Unable to determine without CVSS vector details.

Key dates

06Disclosure timeline

March 11, 2026 CVE published
March 11, 2026 Record updated