The divi-dash WordPress plugin before 1.0.7 does not validate the source of the client IP address it uses for rate limiting and banning, allowing unauthenticated attackers to spoof arbitrary IP addresses in order to bypass rate limiting, ban chosen addresses from the feature, and grow a stored option without bound, resulting in denial of service.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 23 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The divi-dash WordPress plugin before 1.0.7 does not validate the source of the client IP address it uses for rate limiting and banning, allowing unauthenticated attackers to spoof arbitrary IP addresses in order to bypass rate limiting, ban chosen addresses from the feature, and grow a stored option without bound, resulting in denial of service. | |
| Title | Divi Dash < 1.0.7 - Unauthenticated Denial of Service via IP Address Spoofing | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-23T11:01:19.708Z
Reserved: 2026-07-01T12:06:21.422Z
Link: CVE-2026-14321
Updated: 2026-09-23T10:45:11.810Z
Status : Received
Published: 2026-09-23T06:17:00.850
Modified: 2026-09-23T11:17:09.823
Link: CVE-2026-14321
No data.
OpenCVE Enrichment
No data.
Weaknesses