THREAT OPS › Threat News › [NVD] CVE-2026-4361 (MEDIUM 5.0) — The Divi theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.27.6. This is due to the `et_pb_set_video_oembed_thumbnail_resolution()` function using `wp_remote_get()` instead of `wp_safe_remote_get()` to fetch a remote image UR
[NVD] CVE-2026-4361 (MEDIUM 5.0) — The Divi theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.27.6. This is due to the `et_pb_set_video_oembed_thumbnail_resolution()` function using `wp_remote_get()` instead of `wp_safe_remote_get()` to fetch a remote image UR
CVE-2026-4361 CVSS: 5.0 MEDIUM Published: 2026-09-05T07:17:11.930
The Divi theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.27.6. This is due to the `et_pb_set_video_oembed_thumbnail_resolution()` function using `wp_remote_get()` instead of `wp_safe_remote_get()` to fetch a remote image URL, which does not restrict requests to private or res
Indicators of compromise
- CVE-2026-4361cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-4361