---
id: CVE-2026-14321
title: >-
  The divi-dash WordPress plugin before 1.0.7 does not validate the source of
  the client IP address it uses for rate limiting and banning, allowing
  unauthenticated attackers to spoof arbitrary IP addresses in order to bypass
  rate limiting,…
summary: >-
  The divi-dash WordPress plugin before 1.0.7 does not validate the source of
  the client IP address it uses for rate limiting and banning, allowing
  unauthenticated attackers to spoof arbitrary IP addresses in order to bypass
  rate limiting,…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'
cwe:
  - CWE-400
product: divi-dash
affected:
  - divi-dash < 1.0.7
published: '2026-09-23'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T18:13:31.210'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-14321'
references:
  - url: 'https://wpscan.com/vulnerability/6f56b800-c8f6-4cd9-a137-c05b718db201/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00262
epssPercentile: 0.16036
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-23T10:45:15.568605Z'
ingestedAt: '2026-09-23T06:17:57.880Z'
---

## Overview

The divi-dash WordPress plugin before 1.0.7 does not validate the source of the client IP address it uses for rate limiting and banning, allowing unauthenticated attackers to spoof arbitrary IP addresses in order to bypass rate limiting, ban chosen addresses from the feature, and grow a stored option without bound, resulting in denial of service.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
