THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-11613 (CRITICAL 9.8) — The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the

[NVD] CVE-2026-11613 (CRITICAL 9.8) — The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the

mednvdPublished 2026-09-04

CVE-2026-11613 CVSS: 9.8 CRITICAL Published: 2026-09-04T05:17:13.013

The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-11613