PT-2026-85397 · WordPress · Divi Ajax Filter
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Divi Ajax Filter versions prior to 5.1.3
Description
An unauthenticated Local File Inclusion issue exists when the
loop templates parameter is set to 'custom-template'. This allows attackers to include and execute arbitrary .php files on the server via the custom loop template parameter, potentially leading to the execution of PHP code, bypassing access controls, or obtaining sensitive data if .php files can be uploaded.Recommendations
Update Divi Ajax Filter to a version newer than 5.1.2.
Avoid setting the
loop templates parameter to 'custom-template' until the update is applied.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Divi Ajax Filter