Description
The Divi Plus plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 2.4.0 via the 'svg_image' parameter of the /wp-json/elicus/v1/dipl-modules/svg-animator REST endpoint. This is due to the endpoint's permission callback (SVGAnimatorController::index_permission) returning true unconditionally combined with insufficient validation of the 'svg_image' input — sanitize_text_field() and esc_html() do not restrict filesystem paths, the file:// stream wrapper, or arbitrary URLs — before it is passed to file_get_contents() (with a wp_remote_get() fallback) and the raw response body is returned in the JSON 'html' field. This makes it possible for unauthenticated attackers to read arbitrary files on the affected site's server which may make remote code execution possible.
Published: 2026-10-10
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Arbitrary File Read
Action: Immediate Patch
AI Analysis

Impact

The Divi Plus plugin for WordPress incorrectly validates the 'svg_image' parameter on its SVG Animator REST endpoint, allowing any unauthenticated user to read files stored on the server. The endpoint’s permission callback accepts all requests, and sanitization functions applied to the input do not prevent path traversal, usage of the file:// stream wrapper, or arbitrary URLs. Because the file content is returned directly in the JSON response, an attacker can obtain sensitive configuration files, credentials, or other data that may enable further compromise, including potential remote code execution. The weakness is a classic arbitrary file read (CWE‑22).

Affected Systems

WordPress sites using Divi Plus version 2.4.0 or earlier are affected. The vulnerability exists in the Divi Essential plugin bundle that includes Divi Plus. No other products or version ranges are listed as impacted.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. Although the EPSS score is not available, the lack of authentication requirement and the public availability of the vulnerable endpoint increase the likelihood of exploitation. The vulnerability is not listed in CISA's KEV catalog. Attackers can leverage the public REST route to read arbitrary files without any credentials, making this a significant risk for any site still running a vulnerable release of Divi Plus.

Generated by OpenCVE AI on October 10, 2026 at 09:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Divi Plus to version 2.4.1 or newer, which removes the public permission for the SVG Animator endpoint and correctly validates the 'svg_image' parameter.
  • If immediate upgrade is not possible, block or remove access to /wp-json/elicus/v1/dipl-modules/svg-animator via a web‑application firewall or server rule, and disable the endpoint in the plugin configuration if supported.
  • Configure the server or use a security plugin to restrict file_get_contents and wp_remote_get to only allow files within the web root and disallow the file:// stream wrapper, preventing arbitrary path traversal even if the endpoint is accessible.

Generated by OpenCVE AI on October 10, 2026 at 09:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 08:45:00 +0000

Type Values Removed Values Added
Description The Divi Plus plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 2.4.0 via the 'svg_image' parameter of the /wp-json/elicus/v1/dipl-modules/svg-animator REST endpoint. This is due to the endpoint's permission callback (SVGAnimatorController::index_permission) returning true unconditionally combined with insufficient validation of the 'svg_image' input — sanitize_text_field() and esc_html() do not restrict filesystem paths, the file:// stream wrapper, or arbitrary URLs — before it is passed to file_get_contents() (with a wp_remote_get() fallback) and the raw response body is returned in the JSON 'html' field. This makes it possible for unauthenticated attackers to read arbitrary files on the affected site's server which may make remote code execution possible.
Title Divi Plus <= 2.4.0 - Unauthenticated Arbitrary File Read via 'svg_image' Parameter
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T08:26:38.959Z

Reserved: 2026-09-14T19:44:56.205Z

Link: CVE-2026-91136

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T09:16:39.360

Modified: 2026-10-10T09:16:39.360

Link: CVE-2026-91136

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T09:30:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')