CVE-2026-11613 vulnerability and BitFire protection

How BitFire Limits the Impact of CVE-2026-11613

WordPress vulnerability research

BitFire PRO RASP blocks unauthorized PHP-file writes that can turn Divi Ajax Filter file inclusion into persistent server compromise.

Unauthenticated Critical Severity PHP Code Execution Local File Inclusion
BitFire · Vulnerability advisoryResearch published
AdvisoryCVE-2026-11613
ComponentDivi Ajax Filter
Executive summary

What WordPress administrators need to know

CVE-2026-11613 is a critical unauthenticated local file inclusion vulnerability in Divi Ajax Filter versions up to and including 5.1.2. When the `loop_templates` parameter is set to `custom-template`, an attacker can use the `custom_loop_template` parameter to include and execute an arbitrary PHP file already available to the server. The disclosed consequences include bypassing access controls, exposing sensitive data, and executing PHP code, including when an attacker can upload a PHP file and then include it. BitFire PRO RASP adds a decisive filesystem boundary by blocking unauthorized PHP-file creation and modification, preventing the upload-or-write stage of that persistence chain. Version 5.1.3 contains the vendor fix.

At a glance

Key facts

  • Versions up to and including 5.1.2 are affected; version 5.1.3 is patched
  • No authentication is required to exploit the vulnerable behavior
  • Exploitation requires `loop_templates` to be set to `custom-template`
  • The attacker-controlled `custom_loop_template` parameter selects a local PHP file for inclusion
  • Successful inclusion can expose data, bypass access controls, or execute code contained in the selected PHP file
  • BitFire PRO RASP blocks unauthorized PHP-file creation and modification used for payload placement or persistence
01
Vulnerability overview

Understand the exposure

The affected component, attack path, and practical risk for WordPress websites.

Affected componentDivi Ajax Filter
Potential reach2,000,000+ installations
Attack techniquelocal file inclusion
Published2026-09-03
BitFire PRO RASP prevents an unauthenticated request from planting or modifying the PHP file needed to turn file inclusion into durable server compromise.
02
Technical analysis

How the vulnerability works

Research details, affected versions, exploitation behavior, and remediation guidance.

What CVE-2026-11613 Establishes

The disclosure identifies an unauthenticated local file inclusion flaw in Divi Ajax Filter through version 5.1.2. The vulnerable input is the `custom_loop_template` parameter, but the path is exploitable only when `loop_templates` is set to `custom-template`. Under that condition, an attacker can make the plugin include and execute an arbitrary PHP file on the server. Code inside that file then runs in the WordPress PHP process. The stated impact includes access-control bypass, sensitive-data exposure, and code execution where PHP files can be uploaded and included. The brief does not identify an endpoint, HTTP method, source filename, traversal syntax, or patch implementation, so those mechanics should not be assumed.

BitFire PRO RASP Protects the PHP Filesystem Boundary

BitFire PRO RASP enforces filesystem authorization when WordPress or PHP attempts to create or modify a PHP file. An unauthenticated request cannot use an upload handler or another writable path to plant a web shell, backdoor, plugin payload, or other executable PHP file for later inclusion. The same control blocks unauthorized changes to existing WordPress core and plugin PHP files. This protection is independent of a CVE-specific signature: enforcement happens at the protected write operation, after request processing begins but before the unauthorized PHP content is committed. That makes PHP-file protection a strong containment layer for the disclosed upload-and-include scenario.

The Protection Boundary Matters

RASP filesystem protection does not sanitize `custom_loop_template`, patch Divi Ajax Filter, or claim to stop every possible local file inclusion. Its role is precise: it blocks unauthorized creation or modification of PHP files. If an attacker tries to upload or write a PHP payload and then select it through the vulnerable parameter, BitFire PRO RASP stops the required file-write outcome. A PHP file that already exists on the server may present a different inclusion risk, and the disclosure also lists sensitive-data exposure and access-control bypass. Administrators must therefore treat RASP as an independent runtime safeguard, not as permission to leave version 5.1.2 exposed.

If Your Site Was Affected, Investigate for Persistence.

Update Divi Ajax Filter to version 5.1.3 or later immediately, then investigate every site that ran an affected release. Patching closes the disclosed vulnerable path but does not remove PHP payloads or persistence placed before the update. Run BitFire Threat Hunter to look for backdoor WordPress administrator accounts, hidden database triggers, WordPress or server cron persistence, long-running PHP processes, must-use plugins, startup-chain modifications, and droppers capable of restoring malware or reinfecting the site. Remove every discovered persistence mechanism, preserve and review relevant logs, and rotate relevant WordPress, hosting, database, and deployment credentials. The absence of an obvious malicious PHP file does not prove the installation is clean.

Patch Now and Enforce PHP-File Protection

CVE-2026-11613 exposes more than two million Divi Ajax Filter installations to a critical unauthenticated file-inclusion risk under the disclosed custom-template condition. Install version 5.1.3 or later without delay and enable BitFire PRO RASP to deny unauthorized PHP-file creation and modification at runtime. Where earlier exposure is possible, use Threat Hunter to find hidden persistence and complete a disciplined cleanup. BitFire gives administrators a firm filesystem control that prevents an upload or writable code path from becoming a durable PHP foothold while the vendor update removes the known inclusion flaw.

03
Zero-day protection

Protection from the first exploit request

BitFire protects WordPress servers on day zero—before a vulnerability is publicly known and before other vendors have time to develop signatures or patches.

01 · VerifyStop unknown clients

Bot controls and browser verification stop untrusted automated clients before previously unknown exploit code reaches WordPress.

02 · DetectBlock malicious behavior

General WAF protections identify dangerous request behavior and hostile payloads without waiting for a vulnerability-specific signature.

03 · PreventContain attacks at runtime

RASP follows execution inside PHP and prevents unauthorized changes to protected files, accounts, and database content.

BitFire · WordPress protectionZero-day ready
BitFire zero-day WordPress vulnerability protection
BitFire combines verified-client controls, behavior-based WAF detection, and runtime RASP enforcement to protect WordPress before an exploit has a name, CVE, signature, or vendor patch.
About the author

Cory Marsh

Cory has more than 20 years of internet security experience and is a lead developer on the BitFire project.

Read BitFire security research →
Protect your WordPress website

Add protection before the next exploit arrives.

BitFire combines bot controls, request inspection, malware detection, and runtime protection in one WordPress security platform.

Protect my site free →