Junglewise Threat Intelligence

CVE-2026-11613: Divi Ajax Filter local file inclusion via custom_loop_template parameter

CVE-2026-11613 · Severity: critical · CVSS 9.8 · Published 2026-09-04

Vendors: Divi Engine.

Executive brief

The Divi Ajax Filter plugin is a WordPress plugin used to create filterable product and post listings on websites. A Local File Inclusion vulnerability allows unauthenticated attackers to execute arbitrary PHP code on affected sites, potentially leading to complete site compromise, data theft, or malware installation.

Technical details

The vulnerability is a Local File Inclusion (LFI) flaw in the 'custom_loop_template' parameter that allows unauthenticated attackers to include and execute arbitrary PHP files. The flaw is only exploitable when the loop_templates parameter is set to 'custom-template'. An attacker can leverage this to bypass access controls, obtain sensitive data, or achieve code execution if PHP files can be uploaded and included on the server. The vulnerability affects all versions up to and including 5.1.2.

Affected products

  • Divi Engine Divi Ajax Filter up to and including 5.1.2

Timeline

  • 2026-09-04: disclosed

References