<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Elicus - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/elicus/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 09:52:16 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/elicus/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Arbitrary File Read Vulnerability in Divi Plus Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-divi-plus-file-read/</link><pubDate>Sat, 10 Oct 2026 09:52:16 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-divi-plus-file-read/</guid><description>The Divi Plus WordPress plugin contains an arbitrary file read vulnerability (CVE-2026-91136) in the SVG animator REST endpoint that allows unauthenticated attackers to exfiltrate sensitive server files.</description><content:encoded><![CDATA[<p>The Divi Plus plugin for WordPress, in versions up to and including 2.4.0, is susceptible to an arbitrary file read vulnerability (CVE-2026-91136). The flaw resides in the /wp-json/elicus/v1/dipl-modules/svg-animator REST API endpoint, specifically within the 'svg_image' parameter. The plugin's permission callback, SVGAnimatorController::index_permission, fails to enforce authentication, allowing unauthenticated requests to reach the vulnerable code. Input validation is insufficient; the plugin utilizes sanitize_text_field() and esc_html(), which do not prevent the use of filesystem paths, the file:// stream wrapper, or remote URLs. These inputs are subsequently passed to file_get_contents() or a fallback wp_remote_get(), with the resulting file contents returned in the 'html' field of the JSON response. This vulnerability poses a significant risk as it allows attackers to read sensitive configuration files, potentially facilitating further exploitation and remote code execution.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an unauthenticated attacker to read arbitrary files from the WordPress server filesystem. This can lead to the exposure of sensitive data such as wp-config.php, database credentials, environment variables, and site keys, which can be leveraged to achieve full site takeover or remote code execution.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately update the Divi Plus plugin to a version patched against CVE-2026-91136.</li>
<li>Monitor web server logs for HTTP requests directed to '/wp-json/elicus/v1/dipl-modules/svg-animator' with parameters containing path traversal sequences or stream wrappers (e.g., file://, /etc/passwd).</li>
<li>If an update is not immediately feasible, disable the affected REST endpoint via a web application firewall (WAF) rule blocking access to the specific API URI.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>wordpress</category><category>vulnerability</category><category>web-application</category></item></channel></rss>