CVE-2026-3853 | Elegant mes Divi Plugin up to 4.27.6 on WordPress et_pb_video_slider_item custom.unified.js esc_url_raw image_src cross site scripting
A vulnerability classified as problematic has been found in Elegant mes Divi Plugin up to 4.27.6 on WordPress. The affected element is the function esc_url_raw of the file custom.unified.js of the component et_pb_video_slider_item. The manipulation of the argument image_src leads to cross site scripting.
This vulnerability is documented as CVE-2026-3853. The attack can be initiated remotely. There is not any exploit available.VulDB Recent EntriesRead More