CVE-2026-4275 Details
Description
The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.3. This is due to the use of '__return_true' as the permission_callback for the /install_plugin and /activate_plugin REST API endpoints, which bypasses WordPress's built-in REST API nonce verification. Although the endpoint callbacks contain internal current_user_can() checks, the absence of nonce verification means that a forged cross-site request from a logged-in administrator's browser will pass the capability check via the admin's session cookies. This makes it possible for unauthenticated attackers to install arbitrary plugins from WordPress.
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Divi Torque Lite WordPress plugin, specifically in versions through 4.2.3. The issue arises from the '/install_plugin' and '/activate_plugin' REST API endpoints, which use '__return_true' as the permission callback. This configuration bypasses WordPress's standard nonce verification, allowing unauthenticated attackers to exploit the vulnerability. Although the endpoint callbacks include checks for user capabilities, the lack of nonce protection enables forged cross-site requests from logged-in administrators to pass these checks using the admin's session cookies. As a result, attackers can install arbitrary plugins from the WordPress Plugin Directory.
Users are advised to update the Divi Torque Lite WordPress plugin to version 4.3.0 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 9, 2026CISA-ADP
Assessed Jul 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Divi Torque Lite | <= 4.2.3 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | New CVE Received | [email protected] |
Volerion