THREAT OPS › Threat News › [NVD] CVE-2026-11613 (CRITICAL 9.8) — The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the
[NVD] CVE-2026-11613 (CRITICAL 9.8) — The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the
CVE-2026-11613 CVSS: 9.8 CRITICAL Published: 2026-09-04T05:17:13.013
The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in
Indicators of compromise
- CVE-2026-11613cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-11613