Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 23 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The divi-dash WordPress plugin before 1.0.7 does not validate the source of the client IP address it uses for rate limiting and banning, allowing unauthenticated attackers to spoof arbitrary IP addresses in order to bypass rate limiting, ban chosen addresses from the feature, and grow a stored option without bound, resulting in denial of service. | |
| Title | Divi Dash < 1.0.7 - Unauthenticated Denial of Service via IP Address Spoofing | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-23T11:01:19.708Z
Reserved: 2026-07-01T12:06:21.422Z
Link: CVE-2026-14321
Updated: 2026-09-23T10:45:11.810Z
Status : Received
Published: 2026-09-23T06:17:00.850
Modified: 2026-09-23T11:17:09.823
Link: CVE-2026-14321
No data.
OpenCVE Enrichment
Updated: 2026-09-23T14:15:06Z