Impact
The Divi Plus plugin for WordPress incorrectly validates the 'svg_image' parameter on its SVG Animator REST endpoint, allowing any unauthenticated user to read files stored on the server. The endpoint’s permission callback accepts all requests, and sanitization functions applied to the input do not prevent path traversal, usage of the file:// stream wrapper, or arbitrary URLs. Because the file content is returned directly in the JSON response, an attacker can obtain sensitive configuration files, credentials, or other data that may enable further compromise, including potential remote code execution. The weakness is a classic arbitrary file read (CWE‑22).
Affected Systems
WordPress sites using Divi Plus version 2.4.0 or earlier are affected. The vulnerability exists in the Divi Essential plugin bundle that includes Divi Plus. No other products or version ranges are listed as impacted.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. Although the EPSS score is not available, the lack of authentication requirement and the public availability of the vulnerable endpoint increase the likelihood of exploitation. The vulnerability is not listed in CISA's KEV catalog. Attackers can leverage the public REST route to read arbitrary files without any credentials, making this a significant risk for any site still running a vulnerable release of Divi Plus.
OpenCVE Enrichment