CVE-2026-91136: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-91136 is an Arbitrary File Read vulnerability in the Divi Plus plugin for WordPress, affecting versions up to and including 2.4.0. The flaw resides in the /wp-json/elicus/v1/dipl-modules/svg-animator REST endpoint, where the svg_image parameter is passed to file_get_contents() without adequate validation, allowing unauthenticated attackers to read arbitrary files on the server. It was published on October 10, 2026, with a patch available as of the same date. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (Github Advisory).

Technical details

The root cause is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal). The endpoint's permission callback (SVGAnimatorController::index_permission) unconditionally returns true, bypassing any authentication or authorization check. While the svg_image input is processed through sanitize_text_field() and esc_html(), neither function restricts filesystem paths, the file:// stream wrapper, or arbitrary URLs. The sanitized value is then passed directly to file_get_contents() (with a wp_remote_get() fallback), and the raw file contents are returned in the JSON html field of the response, exposing server-side files to any unauthenticated network requester (Github Advisory).

Impact

Successful exploitation allows unauthenticated remote attackers to read arbitrary files on the web server, including sensitive configuration files (e.g., wp-config.php containing database credentials), application source code, and system files such as /etc/passwd. Exposure of database credentials or secret keys could facilitate further attacks including database compromise, authentication bypass, or remote code execution. The vulnerability has no integrity or availability impact in isolation, but the confidentiality breach it enables can serve as a stepping stone for full site compromise (Github Advisory).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Github Advisory). The vulnerability does not require authentication, privileges, or user interaction, making it trivially exploitable if a PoC becomes available. The CVE status is listed as "Received" and it has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported at this time.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Divi Plus plugin (version ≤ 2.4.0) using tools like WPScan, Shodan, or by checking publicly accessible plugin metadata at /wp-content/plugins/divi-plus/readme.txt.
  2. Confirm endpoint availability: Send a GET or POST request to https://<target>/wp-json/elicus/v1/dipl-modules/svg-animator to verify the REST endpoint is accessible and returns a JSON response (no authentication required due to the unconditional true permission callback).
  3. Craft malicious payload: Construct a request with the svg_image parameter set to a local filesystem path using the file:// stream wrapper, e.g., file:///var/www/html/wp-config.php or file:///etc/passwd.
  4. Send the request: Submit the crafted request (e.g., via curl):
    curl -s -X POST 'https://<target>/wp-json/elicus/v1/dipl-modules/svg-animator' \
      -H 'Content-Type: application/json' \
      -d '{"svg_image": "file:///var/www/html/wp-config.php"}'
  5. Extract sensitive data: Parse the JSON response body — the raw file contents are returned in the html field, exposing database credentials, secret keys, or other sensitive configuration data.
  6. Escalate: Use extracted credentials (e.g., WordPress DB credentials from wp-config.php) to access the database, escalate privileges, or achieve remote code execution through secondary attack vectors (Github Advisory).

Indicators of compromise

  • Network: Unusual POST or GET requests to /wp-json/elicus/v1/dipl-modules/svg-animator from unexpected or external IP addresses; requests containing file://, ../, or absolute filesystem paths in the svg_image parameter body.
  • Logs: Web server access logs (Apache/Nginx) showing repeated requests to the SVG animator REST endpoint with non-SVG URL values in the request body; HTTP 200 responses to the endpoint from unauthenticated sources returning large payloads.
  • Application Logs: WordPress debug logs or error logs referencing file_get_contents() calls with filesystem paths or file:// URIs originating from the SVGAnimatorController.
  • File System: No direct file system artifacts expected from read-only exploitation, but subsequent attacker activity may include new PHP webshells or modified plugin files if credentials obtained are leveraged for further access.

Mitigation and workarounds

The primary remediation is to update the Divi Plus plugin to a version newer than 2.4.0, which addresses the insufficient validation and unconditional permission callback (Github Advisory). If immediate patching is not possible, restrict access to the /wp-json/elicus/v1/dipl-modules/svg-animator endpoint via web server configuration (e.g., Nginx location block or Apache .htaccess deny rules) or a WordPress security plugin such as Wordfence. Additionally, consider disabling the WordPress REST API for unauthenticated users as a broader defensive measure until the patch can be applied.

Community reactions

The vulnerability was reported to the GitHub Advisory Database and NVD on October 10, 2026, with Wordfence credited as the source of the CVE assignment (security@wordfence.com). A Wordfence threat intelligence entry exists for this vulnerability. No notable public researcher commentary, social media discussion, or significant media coverage has been identified beyond standard vulnerability database aggregation at this time (Github Advisory).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-91136HIGH7.5
  • divi-plus
NoYesOct 10, 2026
CVE-2026-107657HIGH7.2
  • hivepress
NoYesOct 10, 2026
CVE-2026-89269MEDIUM6.8
  • testimonial-widgets
NoNoOct 10, 2026
CVE-2026-4791MEDIUM6.4
  • peprodev-ups
NoYesOct 10, 2026
CVE-2026-89271MEDIUM5.3
  • wp-businessdirectory
NoNoOct 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management