Sceawere

Vulnerability Detail

CVE-2026-91136UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Divi Plus Arbitrary File Read

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
Divi Essential
Product
Divi Plus
Attack Type
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Divi Plus plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 2.4.0 via the 'svg_image' parameter of the /wp-json/elicus/v1/dipl-modules/svg-animator REST endpoint. This is due to the endpoint's permission callback (SVGAnimatorController::index_permission) returning true unconditionally combined with insufficient validation of the 'svg_image' input — sanitize_text_field() and esc_html() do not restrict filesystem paths, the file:// stream wrapper, or arbitrary URLs — before it is passed to file_get_contents() (with a wp_remote_get() fallback) and the raw response body is returned in the JSON 'html' field. This makes it possible for unauthenticated attackers to read arbitrary files on the affected site's server which may make remote code execution possible.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-10T09:16:39.360Z",
  "pubdate": "2026-10-10T09:16:39.360Z",
  "executiveSummary": "The Divi Plus WordPress plugin, in versions up to and including 2.4.0, contains an Arbitrary File Read vulnerability within its REST API endpoint. This flaw allows unauthenticated remote attackers to bypass security restrictions and retrieve sensitive files from the underlying server filesystem. The vulnerability stems from improper input validation and an insecure permission callback in the SVG animator module. Successful exploitation grants an attacker the ability to read configuration files, such as wp-config.php, which often contain database credentials, secret keys, and other sensitive environment variables. Exposure of these credentials can facilitate further compromise of the WordPress installation, potentially leading to full site takeover or remote code execution. Given the lack of authentication requirements and the accessibility of the endpoint via standard network requests, this vulnerability poses a high risk to the confidentiality and integrity of affected WordPress deployments.",
  "technicalDetails": "The vulnerability is located in the /wp-json/elicus/v1/dipl-modules/svg-animator REST API endpoint, which is handled by the SVGAnimatorController class within the Divi Plus plugin. The root cause of this security flaw is twofold: an insecure permission callback and improper sanitization of user-supplied data before it is processed by filesystem-accessing functions.\nFirst, the index_permission method within the SVGAnimatorController class is implemented to unconditionally return true. This design flaw effectively bypasses the WordPress REST API permission system, allowing any unauthenticated user to access the endpoint without requiring specific roles or capabilities.\nSecond, the endpoint accepts an 'svg_image' parameter intended to process SVG files. However, the input provided to this parameter is passed through insufficient sanitization routines: sanitize_text_field() and esc_html(). These functions are inadequate for security purposes in this context as they do not sanitize or block filesystem paths, the file:// stream wrapper, or external URLs. Consequently, the application passes this unsanitized input directly into a file_get_contents() call, which includes a fallback mechanism using wp_remote_get().\nThe exploitation flow proceeds as follows: An unauthenticated attacker sends a crafted GET or POST request to the /wp-json/elicus/v1/dipl-modules/svg-animator endpoint, supplying a sensitive server-side file path or URL in the 'svg_image' parameter. Because the controller lacks authorization checks, the server proceeds to execute the request. The application attempts to read the target resource (e.g., /var/www/html/wp-config.php) via file_get_contents(). The resulting file content is then returned to the user in the 'html' field of the JSON response body. By leveraging path traversal sequences or stream wrappers, an attacker can read virtually any file accessible to the web server process. The impact of this disclosure is critical; access to wp-config.php frequently yields database credentials, which can be leveraged to modify site content or escalate privileges. Furthermore, the capability to retrieve arbitrary files significantly aids an attacker in performing reconnaissance and discovering additional attack vectors for remote code execution."
}
CVE-2026-91136: Divi Plus Arbitrary File Read (HIGH Severity, CVSS: 7.5) | Sceawere