CPE
The Divi Plus WordPress plugin contains an arbitrary file read vulnerability (CVE-2026-91136) in the SVG animator REST endpoint that allows unauthenticated attackers to exfiltrate sensitive server files.