Executive brief
The Divi Ajax Filter plugin is a WordPress plugin used to create filterable product and post listings on websites. A Local File Inclusion vulnerability allows unauthenticated attackers to execute arbitrary PHP code on affected sites, potentially leading to complete site compromise, data theft, or malware installation.
Technical details
The vulnerability is a Local File Inclusion (LFI) flaw in the 'custom_loop_template' parameter that allows unauthenticated attackers to include and execute arbitrary PHP files. The flaw is only exploitable when the loop_templates parameter is set to 'custom-template'. An attacker can leverage this to bypass access controls, obtain sensitive data, or achieve code execution if PHP files can be uploaded and included on the server. The vulnerability affects all versions up to and including 5.1.2.
Affected products
- Divi Engine Divi Ajax Filter up to and including 5.1.2
Timeline
- 2026-09-04: disclosed