Arbitrary File Read Vulnerability in Divi Plus Plugin for WordPress
CVE-2026-91136

7.5HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
10 October 2026

What is CVE-2026-91136?

The Divi Plus plugin for WordPress contains a vulnerability that allows unauthenticated attackers to read arbitrary files on the server. This vulnerability originates from an insufficiently secured REST endpoint, which does not validate the 'svg_image' parameter properly. Consequently, under certain conditions, attackers can exploit this weakness to gain unauthorized access to sensitive files, potentially leading to remote code execution. The lack of appropriate permission checks within the SVGAnimatorController::index_permission method further compounds the risk, making it crucial for users to apply the recommended updates to secure their sites.

Affected Version(s)

Divi Plus 0 <= 2.4.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ShinThink
.