The Divi Ajax Filter plugin for WordPress contains a Local File Inclusion (LFI) vulnerability affecting all versions up to and including 5.1.2. The flaw exists in the 'custom_loop_template' parameter and allows unauthenticated attackers to include and execute arbitrary PHP files on the server. Successful exploitation can lead to access control bypass, sensitive data exposure, or full remote code execution if PHP files can be uploaded. The vulnerability is conditionally exploitable only when the 'loop_templates' parameter is set to 'custom-template'. No authentication is required, making this a significant risk for any WordPress site running the affected plugin versions. A patch or updated version is expected as referenced in the Divi Engine changelog. The issue has been documented by both NVD and Wordfence threat intelligence.