
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-91136 is an Arbitrary File Read vulnerability in the Divi Plus plugin for WordPress, affecting versions up to and including 2.4.0. The flaw resides in the /wp-json/elicus/v1/dipl-modules/svg-animator REST endpoint, where the svg_image parameter is passed to file_get_contents() without adequate validation, allowing unauthenticated attackers to read arbitrary files on the server. It was published on October 10, 2026, with a patch available as of the same date. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (Github Advisory).
The root cause is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal). The endpoint's permission callback (SVGAnimatorController::index_permission) unconditionally returns true, bypassing any authentication or authorization check. While the svg_image input is processed through sanitize_text_field() and esc_html(), neither function restricts filesystem paths, the file:// stream wrapper, or arbitrary URLs. The sanitized value is then passed directly to file_get_contents() (with a wp_remote_get() fallback), and the raw file contents are returned in the JSON html field of the response, exposing server-side files to any unauthenticated network requester (Github Advisory).
Successful exploitation allows unauthenticated remote attackers to read arbitrary files on the web server, including sensitive configuration files (e.g., wp-config.php containing database credentials), application source code, and system files such as /etc/passwd. Exposure of database credentials or secret keys could facilitate further attacks including database compromise, authentication bypass, or remote code execution. The vulnerability has no integrity or availability impact in isolation, but the confidentiality breach it enables can serve as a stepping stone for full site compromise (Github Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Github Advisory). The vulnerability does not require authentication, privileges, or user interaction, making it trivially exploitable if a PoC becomes available. The CVE status is listed as "Received" and it has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported at this time.
/wp-content/plugins/divi-plus/readme.txt.https://<target>/wp-json/elicus/v1/dipl-modules/svg-animator to verify the REST endpoint is accessible and returns a JSON response (no authentication required due to the unconditional true permission callback).svg_image parameter set to a local filesystem path using the file:// stream wrapper, e.g., file:///var/www/html/wp-config.php or file:///etc/passwd.curl):curl -s -X POST 'https://<target>/wp-json/elicus/v1/dipl-modules/svg-animator' \
-H 'Content-Type: application/json' \
-d '{"svg_image": "file:///var/www/html/wp-config.php"}'html field, exposing database credentials, secret keys, or other sensitive configuration data.wp-config.php) to access the database, escalate privileges, or achieve remote code execution through secondary attack vectors (Github Advisory)./wp-json/elicus/v1/dipl-modules/svg-animator from unexpected or external IP addresses; requests containing file://, ../, or absolute filesystem paths in the svg_image parameter body.file_get_contents() calls with filesystem paths or file:// URIs originating from the SVGAnimatorController.The primary remediation is to update the Divi Plus plugin to a version newer than 2.4.0, which addresses the insufficient validation and unconditional permission callback (Github Advisory). If immediate patching is not possible, restrict access to the /wp-json/elicus/v1/dipl-modules/svg-animator endpoint via web server configuration (e.g., Nginx location block or Apache .htaccess deny rules) or a WordPress security plugin such as Wordfence. Additionally, consider disabling the WordPress REST API for unauthenticated users as a broader defensive measure until the patch can be applied.
The vulnerability was reported to the GitHub Advisory Database and NVD on October 10, 2026, with Wordfence credited as the source of the CVE assignment (security@wordfence.com). A Wordfence threat intelligence entry exists for this vulnerability. No notable public researcher commentary, social media discussion, or significant media coverage has been identified beyond standard vulnerability database aggregation at this time (Github Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."