Impact
The Divi Ajax Filter plugin for WordPress is vulnerable to unauthenticated Local File Inclusion via the \"custom_loop_template\" parameter. This weakness, mapped to CWE‑98, allows an attacker to force the server to include and execute arbitrary .php files, giving the ability to run arbitrary PHP code, bypass access controls, and exfiltrate or modify sensitive data.
Affected Systems
All installations of Divi Ajax Filter with versions up to and including 5.1.2 are affected. An attacker can exploit the flaw only when the plugin’s loop_templates option is set to \"custom-template\", enabling the vulnerable custom_loop_template parameter.
Risk and Exploitability
The vulnerability receives a CVSS score of 9.8, indicating a critical level of risk. The EPSS score is not available, but the fact that this flaw can be exploited without authentication and leads to code execution places it at a very high threat level. The vulnerability is not currently listed in the CISA KEV catalog, yet its high severity and potential for local file inclusion make it a priority for remediation.
OpenCVE Enrichment