{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/divi-ajax-filter--5.1.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:divi:ajax_filter:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-11613"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Divi Ajax Filter (\u003c= 5.1.2)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","lfi","web-application","rce"],"_cs_type":"advisory","_cs_vendors":["Divi"],"content_html":"\u003cp\u003eThe Divi Ajax Filter plugin for WordPress contains a critical Local File Inclusion (LFI) vulnerability, tracked as CVE-2026-11613, affecting all versions up to and including 5.1.2. The vulnerability resides in the handling of the 'custom_loop_template' parameter. An unauthenticated attacker can exploit this flaw by setting the 'loop_templates' parameter to 'custom-template', which fails to adequately sanitize user input. If an attacker can successfully upload a malicious PHP file to the server or otherwise gain control over a local file, they can include and execute that file to achieve Remote Code Execution (RCE). This vulnerability poses a severe risk to WordPress installations as it allows for complete site compromise, data exfiltration, and unauthorized access to system resources. Defenders should prioritize updating the plugin immediately upon the release of a patch.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-11613 allows unauthenticated attackers to execute arbitrary PHP code on the target web server. This can lead to total server compromise, unauthorized access to sensitive database content, and the potential to move laterally within the hosting environment. The impact is critical, as it bypasses standard access controls to facilitate RCE.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Divi Ajax Filter plugin to the latest available version beyond 5.1.2 immediately to remediate the vulnerable parameter handling.\u003c/li\u003e\n\u003cli\u003eImplement strict file upload restrictions to prevent attackers from placing malicious PHP scripts that could be leveraged by this LFI vulnerability.\u003c/li\u003e\n\u003cli\u003eDeploy Web Application Firewall (WAF) rules to inspect incoming requests for anomalous values in the 'custom_loop_template' and 'loop_templates' parameters.\u003c/li\u003e\n\u003cli\u003eAudit existing WordPress plugins for unauthorized or outdated components that could be targeted via similar LFI vectors.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T05:24:21Z","date_published":"2026-09-04T05:24:21Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-11613/","summary":"An unauthenticated Local File Inclusion (LFI) vulnerability in the Divi Ajax Filter plugin for WordPress enables attackers to execute arbitrary PHP code via the custom_loop_template parameter.","title":"Local File Inclusion Vulnerability in Divi Ajax Filter","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-11613/"}],"language":"en","title":"CraftedSignal Threat Feed - Divi Ajax Filter (\u003c= 5.1.2)","version":"https://jsonfeed.org/version/1.1"}