CVE-2026-5118Disclosure

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2. This is due to the plugin accepting a user-controlled 'role' parameter from POST data during user registration without validating it against the form's configured default_user_role setting. This makes it possible for unauthenticated attackers to create administrator accounts by tampering with the role parameter during registration.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-09-25)
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-05-21: 1Mentions · 2026-05-23: 1Mentions · 2026-09-25: 3PoC Mentioned / Linked · 2026-09-25: 2Active Exploitation · 2026-09-25: 1Patch / Workaround · 2026-05-21: 1Technical Details · 2026-05-21: 1Technical Details · 2026-05-23: 105-2105-2309-25
Signal classification3 categories
Disclosure
360.0%
Active Exploitation
120.0%
PoC
120.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-211
Disclosure1
2026-05-231
Disclosure1
2026-09-253
Active Exploitation1Disclosure1PoC1
Full discourse5 posts
  • ExploitGrid@exploitgrid
    Active Exploitation

    💀 CRITICAL Exploits Trending ├ CVE-2026-27626 · CVE-2026-86218 · PoC live ├ CVE-2020-14645 — WebLogic · PoC live (still getting hit 6 yrs later) └ CVE-2026-5118 · CVE-2026-62878 · PoC live

    Post summary

    The post highlights trending CVEs with publicly available PoCs and explicitly confirms active exploitation of CVE-2020-14645 (WebLogic) six years post-disclosure.

    1000056
    330 followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [EXPLOIT] CVE-2026-5118 [CRITICAL/PoC] CVE-2026-5118 🔗 https://exploitgrid.net/exploits/eb2f7ab4-248f-46d0-92c8-c9de49bb93a3

    Post summary

    The post highlights CVE-2026-5118 as critical and shares a link to a Proof of Concept exploit, focusing on the availability of the PoC.

    1000042
    330 followersView on X
  • ExploitGrid@exploitgrid
    Disclosure

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: CVE-2026-27626 CVE-2026-86218 CVE-2020-14645 CVE-2026-5118 CVE-2026-62878 ..🧵👇

    Post summary

    The tweet announces several CVEs as 'Critical Exploits disclosed today' without providing technical details, PoC code, exploit tools, patch information, or evidence of active wild exploitation, fitting a disclosure-type post.

    1000060
    330 followersView on X
  • Orizon@OrizonCyber
    Disclosure

    🚨 CVE-2026-5118 — CVSS 9.8/10 ██████████ The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including,... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/q9jguX6KJP

    Post summary

    The tweet announces CVE-2026-5118 as a critical privilege‑escalation flaw in Divi Form Builder and urges users to apply the patch.

    10000292
    43 followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🚨 THREE WordPress plugins, THREE critical 9.8 CVSS vulnerabilities, all unauthenticated. 🔴 Avada Builder (CVE-2026-6279) 🔴 Divi Form Builder (CVE-2026-5118) 🔴 BookingPress Pro (CVE-2026-6960) 🔗 https://threataft.com/articles/wordpress-triple-threat-9-8-cvss-avada-divi-bookingpress #CyberSecurity #WordPress #CVE20266279 #CVE20265118

    Post summary

    The post announces three high‑severity, unauthenticated vulnerabilities affecting WordPress plugins and links to an article for more details, but it lacks PoC, exploit code, patch information, or evidence of active exploitation.

    00000261
    26 followersView on X

Explore more