CVE-2026-11613 is an unauthenticated local file inclusion vulnerability in the Divi Ajax Filter plugin for WordPress affecting versions through 5.1.2. The plugin does not safely constrain the custom_loop_template parameter when the loop_templates setting is configured as custom-template. An unauthenticated remote attacker can cause the application to include PHP files already present on the server and execute their PHP contents in the WordPress process context.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
The repository contains two files: a Markdown README and `poc.py`, a standalone Python 3 proof-of-concept and concurrent live scanner. Despite the README describing a larger lab and auxiliary tooling, those referenced files are not present in the analyzed repository. The Python tool accepts manually supplied hosts or a target list, normalizes URLs, fetches public pages to extract a 10-character WordPress AJAX nonce, checks plugin version artifacts, and sends crafted unauthenticated requests to WordPress `admin-ajax.php`. It tests both Divi Ajax Filter AJAX actions and multiple traversal depths, attempting to make the plugin include local files via the unsanitized `custom_loop_template` field. It validates LFI from characteristic response content and can optionally test execution of an already-existing PHP file by checking an operator-defined marker. No exploit framework is used, and no file-upload, shell deployment, persistence, or target discovery capability is present. The README's claimed vulnerable flow is a CWE-98 path traversal/local include in Divi Ajax Filter's custom loop-template inclusion logic, with RCE dependent on a separately attainable PHP file on the target.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated local file inclusion vulnerability in Divi Ajax Filter for WordPress through version 5.1.2. When custom templates are enabled, an attacker can include and execute arbitrary PHP files present on the server, potentially bypassing access controls, accessing sensitive data, or achieving code execution where PHP files can be uploaded and included.
A critical unauthenticated local file inclusion vulnerability in the Divi Ajax Filter WordPress plugin through version 5.1.2. When the loop_templates parameter is set to 'custom-template', an attacker can use custom_loop_template to include and execute arbitrary PHP files already present on the server, potentially bypassing access controls, exposing sensitive data, or achieving code execution.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.