CVE-2026-5118
Divi Form Builder <= 5.1.2 - Unauthenticated Privilege Escalation via 'role'
- Published
- May 21, 2026
- Updated
- May 21, 2026
- Assigning CNA
- Wordfence
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HLow · next 30 days
- Percentile
- 40.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2. This is due to the plugin accepting a user-controlled 'role' parameter from POST data during user registration without validating it against the form's configured default_user_role setting. This makes it possible for unauthenticated attackers to create administrator accounts by tampering with the role parameter during registration.
Sources
6- CVE-2026-5118Exploit
Automated exploit and mass scanner for CVE-2026-5118, an unauthenticated privilege escalation in WordPress Divi Form Builder <=5.1.2, enabling admin account creation via role injection.
- CVE-2026-5118Exploit
Divi Form Builder <= 5.1.2 — Unauthenticated Privilege Escalation via Role Injection
- CVE-2026-5118Exploit
CVE-2026-5118 | Divi Form Builder <= 5.1.2 | Unauthenticated Privilege Escalation via Role Injection
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.