---
cve: "CVE-2026-14321"
severity: "HIGH"
cvss: 8.2
epss: "0.2%"
vendor: "Unknown"
kev: false
exploited: false
published: "2026-09-23 06:17:00"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-26T16:04:28+02:00"
---

# CVE-2026-14321

> 8.2 HIGH

## Beschreibung

The divi-dash WordPress plugin before 1.0.7 does not validate the source of the client IP address it uses for rate limiting and banning, allowing unauthenticated attackers to spoof arbitrary IP addresses in order to bypass rate limiting, ban chosen addresses from the feature, and grow a stored option without bound, resulting in denial of service.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Keine | good |
| I Integrität | Gering | warn |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <https://wpscan.com/vulnerability/6f56b800-c8f6-4cd9-a137-c05b718db201/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-14321) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
