CVE-2026-11613 carries a CVSS 3.1 base score of 9.8 against Divi Ajax Filter, a WordPress plugin published by Divi Engine that adds AJAX-based filtering to Divi-built sites. NVD classifies it as CWE-98 (PHP Remote File Inclusion) and describes a local-file-inclusion vulnerability affecting releases up to and including 5.1.2. VulnCheck’s KEV feed reports the CVE as exploited, dated September 10, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2026-11613 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion on September 19, 2026. VulnCheck’s catalog admits vendor and researcher exploitation reporting that CISA’s own listing criteria have not (yet) accepted; no Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
NVD’s description names the vulnerable parameter directly: the custom_loop_template parameter is used to build a file path that the plugin then includes and executes as PHP, without the parameter being validated against an allow-list of legitimate template files. An unauthenticated attacker who controls that parameter’s value can point it at an arbitrary .php file already present on the server and have the plugin execute it — which is why NVD’s title frames this specifically as CWE-98, the PHP-specific remote-file-inclusion pattern, rather than a generic path-traversal read.
NVD states one precondition explicitly: the vulnerability is only exploitable when the plugin’s loop_templates parameter is set to 'custom-template'. That is a plugin-configuration state, not a site-wide toggle a defender is likely to have visibility into without checking directly — Divi’s page-builder templates can set this per-module, so the exposed surface depends on how a given site’s Divi layouts use the Ajax Filter component, not on whether the plugin is merely installed and active.
Because the flaw includes and executes arbitrary .php files rather than returning file contents, NVD’s own description reaches “execution of any PHP code in those files” as a direct consequence — the practical severity depends on whether the attacker can also get a .php file onto the server through some other means (a file upload feature elsewhere in the stack, for instance), at which point this becomes the execution primitive. Absent that second ingredient, the same bug still permits reading and including other PHP files already on disk, which NVD notes can be used to “bypass access controls” or “obtain sensitive data” even without full code execution.
Evidence and confidence
- Medium confidence — the CVSS 9.8 score, the vector (
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), the CWE-98 classification, the vulnerablecustom_loop_templateparameter, theloop_templates: 'custom-template'precondition, and the 5.1.2 affected-version ceiling all trace to NVD alone. The exploitation report traces to VulnCheck KEV alone. - Unknown — exploitation probability. FIRST’s EPSS model scores this CVE 0.00455, 38.6th percentile as of our ingestion — below the midpoint of the broader EPSS population, which is not itself evidence against the VulnCheck exploitation report but does not independently corroborate it either.
No field is in conflict between our two sources. Our data carries no structured fixed-version field; NVD names 5.1.2 only as the affected ceiling, not the version that resolves the issue. We also found no third-party security-research coverage of this specific CVE in a broader search at the time of writing — a contrast with the volume of independent analysis already published on other WordPress-plugin CVEs in this same KEV window, worth noting as a gap in visibility rather than a signal about the bug’s real-world severity.
Why this matters
The loop_templates: 'custom-template' precondition means exposure varies by how a given site’s Divi layouts actually use this plugin’s filtering feature, not by plugin version alone — two sites running the identical vulnerable release can have meaningfully different exposure depending on module configuration. That makes a version check necessary but not sufficient for a defender assessing risk; confirming whether any Divi module on the site sets loop_templates to custom-template is the more precise question.
Local file inclusion that reaches arbitrary PHP execution is a severe outcome regardless of catalog status, and NVD’s own description supports treating this as unauthenticated code execution under the stated precondition. The VulnCheck exploitation report adds urgency on top of that severity case, though it remains uncorroborated by any second source in our data.
Frequently Asked Questions
What is CVE-2026-11613? A CVSS 9.8 local file inclusion vulnerability (CWE-98) in Divi Ajax Filter, a WordPress plugin from Divi Engine, that NVD states allows unauthenticated attackers to include and execute arbitrary PHP files in versions through 5.1.2.
Is CVE-2026-11613 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 10, 2026. That report is single-sourced; CISA has not listed this CVE as of our September 19, 2026 ingestion, and we found no independent corroboration or third-party research coverage. Treat it as reported exploitation, not confirmed.
Do I need a specific configuration for my site to be at risk?
Yes. NVD states the flaw is only exploitable when the plugin’s loop_templates parameter is set to 'custom-template' — a per-layout setting, not necessarily a site-wide one. Installing the plugin alone does not confirm exposure; check how your Divi layouts configure this feature.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed. The severity case for upgrading stands on the CVSS and CWE classification alone.
Which version fixes it? NVD names 5.1.2 as the affected ceiling but does not state a fixed version, and our ingested data carries none. Confirm the remediated release against Divi Engine’s own changelog before considering the upgrade complete.
Severity, vector, weakness classification, vulnerable parameter, configuration precondition, and affected-version ceiling sourced from the National Vulnerability Database record for CVE-2026-11613. Exploitation status and the September 10, 2026 catalog date are reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 19, 2026. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.