CVE-2026-3850 | Elegant mes Divi Plugin up to 4.27.6 on WordPress Contact Form Shortcode class-et-builder-element.php et_pb_contact_form redirect_url cross site scripting (EUVD-2026-69886 / CNNVD-2026-98164500)
A vulnerability classified as problematic has been found in Elegant mes Divi Plugin up to 4.27.6 on WordPress. Affected by this issue is the function et_pb_contact_form of the file class-et-builder-element.php of the component Contact Form Shortcode. This manipulation of the argument redirect_url causes cross site scripting.
This vulnerability is tracked as CVE-2026-3850. The attack is possible to be carried out remotely. No exploit exists.