CVE-2026-11613 is a Local File Inclusion (LFI) vulnerability affecting the Divi Ajax Filter plugin for WordPress in all versions up to and including 5.1.2. The vulnerability exists in the 'custom_loop_template' parameter and allows unauthenticated attackers to include and execute arbitrary PHP files on the server. Exploitation requires the 'loop_templates' parameter to be set to 'custom-template'. Successful exploitation can lead to bypass of access controls, sensitive data disclosure, and remote code execution if PHP files can be uploaded to the server. The vulnerability is exploitable without authentication, significantly raising its risk level. WordPress site administrators using this plugin are advised to update immediately to a patched version.