PatchSiren

Divi Essential CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Divi Essential CVE published 2026-10-10

CVE-2026-91136

The Divi Plus plugin for WordPress, version 2.4.0 or earlier, is vulnerable to unauthenticated arbitrary file read via the 'svg_image' parameter of the /wp-json/elicus/v1/dipl-modules/svg-animator REST endpoint. This vulnerability allows unauthenticated attackers to read arbitrary files on the affected site's server, potentially leading to remote code execution. The endpoint's permission callback returns [truncated]