CVE-2026-19652
Received Received - Intake

Privilege Escalation in Divi Membership WordPress Plugin

Vulnerability report for CVE-2026-19652, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: Wordfence

Description

The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and calling `password_verify()` against an attacker-controlled bcrypt hash supplied in the `form_id` POST parameter, with no validation or whitelist of allowed roles. This makes it possible for unauthenticated attackers to register a new account with the administrator role by submitting a locally computed bcrypt hash of `administrator` as `form_id`, and when `auto_login=on` is submitted, be immediately authenticated as that administrator in the same request, resulting in full site takeover. Exploitation requires a WordPress nonce, but that nonce is publicly emitted on any page rendering the Divi Membership registration form and is therefore obtainable by any unauthenticated visitor.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
divi_engine divi_membership to 2.2.0 (inc)
divi_engine divi_membership to 3.0.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Divi Membership plugin for WordPress has a privilege escalation vulnerability in versions up to 2.2.0. An unauthenticated attacker can register a new user account with administrator privileges by submitting a bcrypt hash of 'administrator' in the form_id parameter. If auto_login is enabled, the attacker is immediately logged in as an admin, allowing full site takeover.

Detection Guidance

Check for unauthorized administrator accounts created via the Divi Membership plugin. Inspect WordPress user roles and registration logs for suspicious activity. Look for POST requests to the registration endpoint with form_id containing bcrypt hashes. Review plugin version in WordPress admin panel to confirm if version 2.2.0 or earlier is installed.

Impact Analysis

This vulnerability allows unauthenticated attackers to gain full administrative access to a WordPress site running the vulnerable Divi Membership plugin. This could lead to complete site compromise, data theft, malware installation, or defacement. Attackers can create new admin accounts, modify site content, or install malicious plugins.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA by allowing unauthorized access to sensitive user data. GDPR requires strict access controls and breach notification, while HIPAA mandates protection of health information. A breach via this vulnerability could result in regulatory fines and legal consequences.

Mitigation Strategies

Immediately update the Divi Membership plugin to the latest version. Disable the plugin if an update is not available. Remove any unauthorized administrator accounts. Monitor user activity and registration logs for signs of exploitation. Implement network-level monitoring for unusual POST requests to the registration endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19652. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart