CVE-2026-91136 | Divi Essential Divi Plus Plugin up to 2.4.0 on WordPress REST Endpoint svg-animator index_permission svg_image
A vulnerability, which was classified as critical, has been found in Divi Essential Divi Plus Plugin up to 2.4.0 on WordPress. Impacted is the function SVGAnimatorController::index_permission of the file /wp-json/elicus/v1/dipl-modules/svg-animator of the component REST Endpoint. This manipulation of the argument svg_image causes permission issues.
The identification of this vulnerability is CVE-2026-91136. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More