CVE-2026-2626

Divi Booster < 5.0.2 - Unauthenticated PHP Object Injection

The divi-booster WordPress plugin before 5.0.2 does not have authorization and CSRF checks in one of its fixing function, allowing unauthenticated users to modify stored divi-booster WordPress plugin before 5.0.2 options. Furthermore, due to the use of unserialize() on the data, this could be further exploited when combined with a PHP gadget chain to achieve PHP Object Injection


We have discovered 1,002 live websites that are affected by CVE-2026-2626.

Run a Free Instant Scan




Common Weakness Enumeration

CWE-502 Deserialization of Untrusted Data



Details

  • Published - Mar 11, 2026
  • Updated - Mar 11, 2026

Credits

  • Saif (Team 51) (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-2626
United States457 websites



Germany109 websites
GB59 websites
Spain59 websites
France41 websites
Netherlands35 websites
Canada33 websites
Australia26 websites
Italy26 websites
South Africa15 websites

Website Distribution by TLD

Number of websites using CVE-2026-2626
.com438 websites
.org136 websites
.de79 websites
.co.uk38 websites
.nl32 websites
.es26 websites
.ca23 websites
.com.au21 websites
.net15 websites
.it14 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-2626

Top websites that are affected by CVE-2026-2626. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.de Germany**,***
***************.com United States**,***
****.org United States**,***
*****************************.org United States***,***
************.se Sweden***,***
**********.de Germany***,***
**************.org United States***,***
*******.com United States***,***
*************.com United States***,***
*******************.**.uk GB***,***
See full domain list