HIGH
Divi Essential
CVE published 2026-10-10
CVE-2026-91136
The Divi Plus plugin for WordPress, version 2.4.0 or earlier, is vulnerable to unauthenticated arbitrary file read via the 'svg_image' parameter of the /wp-json/elicus/v1/dipl-modules/svg-animator REST endpoint. This vulnerability allows unauthenticated attackers to read arbitrary files on the affected site's server, potentially leading to remote code execution. The endpoint's permission callback returns [truncated]