CRITICAL
9.8 CVE-2026-11613 Published 4 Sept 2026
Divi Ajax Filter WordPress Plugin LFI Vulnerability
Worried this affects one of your servers?
The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion (LFI) in versions up to and including 5.1.2.
An unauthenticated attacker can exploit this vulnerability by manipulating the 'custom_loop_template' parameter, allowing them to include and execute arbitrary .php files on the server.
This can lead to bypassing access controls, obtaining sensitive data, or executing arbitrary PHP code if .php file uploads are possible.
This vulnerability is only exploitable when the 'loop_templates' parameter is set to 'custom-template'.
Reference: CVE-2026-11613 on NVD
← Back to Security News