CVE-2024-5647: Badhonrocks Divi Torque Lite
Medium severity, CVSS 6.4. EPSS: 0.4% chance of exploitation in the next 30 days.
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was fixed in the upstream library (Magnific Popups version 1.2.0) by disabling the loading of HTML within certain fields by default.
Affected products
- Badhonrocks Divi Torque Lite: up to and including 4.0.5
- Blossomthemes Blossomthemes Social Feed: up to and including 2.0.5
- Boldthemes Bold Page Builder: up to and including 5.1.2
- Divisupreme Supreme Modules Lite – Divi Theme, Extra Theme And Divi Builder: up to and including 2.5.52
- Elegant Themes Divi: up to and including 4.27.1
- Elegant Themes Divi Builder: up to and including 4.27.1
- Elegant Themes Divi Extra: up to and including 4.27.1
- Gn Themes Shortcodes Ultimate – Content Elements: up to and including 7.4.2
- Gutentor Gutentor – Gutenberg Blocks – Page Builder For Gutenberg Editor: up to and including 3.4.9
- Leevio Happy Addons For Elementor: up to and including 3.12.2
- Muffingroup Betheme: up to and including 28.4
- Oceanwp Oceanwp: up to and including 3.6.0
- Robosoft Robo Gallery – Photo & Image Slider: up to and including 3.2.22
- Sayful Carousel Slider: up to and including 2.2.14
- Wpdevteam Essential Addons For Elementor – Popular Elementor Templates & Widgets: up to and including 6.0.4
Published 2025-07-03. Last modified 2026-08-25.