Skip to content
Threat Feed
high advisory

Arbitrary File Read Vulnerability in Divi Plus Plugin

The Divi Plus WordPress plugin contains an arbitrary file read vulnerability (CVE-2026-91136) in the SVG animator REST endpoint that allows unauthenticated attackers to exfiltrate sensitive server files.

CVE search metadata

CVE search record: CVE-2026-91136. Severity: high. CVSS: 7.5. KEV: no. Product: Divi Plus (<= 2.4.0). Brief: Arbitrary File Read Vulnerability in Divi Plus Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-divi-plus-file-read/

The Divi Plus plugin for WordPress, in versions up to and including 2.4.0, is susceptible to an arbitrary file read vulnerability (CVE-2026-91136). The flaw resides in the /wp-json/elicus/v1/dipl-modules/svg-animator REST API endpoint, specifically within the 'svg_image' parameter. The plugin's permission callback, SVGAnimatorController::index_permission, fails to enforce authentication, allowing unauthenticated requests to reach the vulnerable code. Input validation is insufficient; the plugin utilizes sanitize_text_field() and esc_html(), which do not prevent the use of filesystem paths, the file:// stream wrapper, or remote URLs. These inputs are subsequently passed to file_get_contents() or a fallback wp_remote_get(), with the resulting file contents returned in the 'html' field of the JSON response. This vulnerability poses a significant risk as it allows attackers to read sensitive configuration files, potentially facilitating further exploitation and remote code execution.

Impact

Successful exploitation allows an unauthenticated attacker to read arbitrary files from the WordPress server filesystem. This can lead to the exposure of sensitive data such as wp-config.php, database credentials, environment variables, and site keys, which can be leveraged to achieve full site takeover or remote code execution.

Recommendation

  • Immediately update the Divi Plus plugin to a version patched against CVE-2026-91136.
  • Monitor web server logs for HTTP requests directed to '/wp-json/elicus/v1/dipl-modules/svg-animator' with parameters containing path traversal sequences or stream wrappers (e.g., file://, /etc/passwd).
  • If an update is not immediately feasible, disable the affected REST endpoint via a web application firewall (WAF) rule blocking access to the specific API URI.

Immediate actions

Patch Divi Plus to the version remediating CVE-2026-91136

IT Operations 48h

Mitigations

Block access to /wp-json/elicus/v1/dipl-modules/svg-animator via WAF if patching is delayed

immediate SOC

CVE-2026-91136

Detection coverage 1

Detect CVE-2026-91136 Exploitation - Arbitrary File Read in Divi Plus

high

Detects exploitation of the Divi Plus svg-animator endpoint by looking for path traversal patterns or file stream wrappers in the svg_image parameter.

sigma tactics: exfiltration, initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →