PT-2026-85397 · WordPress · Divi Ajax Filter

·

CVE-2026-11613

·

Published

2026-09-04

·

Updated

2026-09-04

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Divi Ajax Filter versions prior to 5.1.3
Description An unauthenticated Local File Inclusion issue exists when the loop templates parameter is set to 'custom-template'. This allows attackers to include and execute arbitrary .php files on the server via the custom loop template parameter, potentially leading to the execution of PHP code, bypassing access controls, or obtaining sensitive data if .php files can be uploaded.
Recommendations Update Divi Ajax Filter to a version newer than 5.1.2. Avoid setting the loop templates parameter to 'custom-template' until the update is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11613

Affected Products

Divi Ajax Filter