CVE-2026-19660
Received Received - Intake

Authentication Bypass in Divi Membership WordPress Plugin

Vulnerability report for CVE-2026-19660, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: Wordfence

Description

The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature check, no ownership verification, and no nonce, allowing it to trust an entirely attacker-controlled user ID value that is passed directly to `wp_set_current_user()` and `wp_set_auth_cookie()`. This makes it possible for unauthenticated attackers to log in as any existing WordPress user β€” including administrators β€” by supplying an arbitrary user ID in the `paypal_param` GET parameter, resulting in full site takeover. The vulnerability is further compounded by the fact that the PayPal gateway class is instantiated unconditionally regardless of whether PayPal is enabled or configured, ensuring the vulnerable hook is always registered on every front-end request.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
divi_engine divi_membership to 2.3.0 (inc)
divi_engine divi_membership From 3.0.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Divi Membership plugin for WordPress has an authentication bypass flaw in versions up to 2.3.0. The vulnerability is in the process_paypal_callback function, which is hooked to the init action. It accepts a base64-encoded paypal_param GET parameter without validating IPN, cryptographic signatures, ownership, or nonces. This allows attackers to supply an arbitrary user ID that is directly passed to wp_set_current_user() and wp_set_auth_cookie(), enabling unauthenticated login as any user, including administrators, leading to full site takeover.

Detection Guidance

Check if the Divi Membership plugin version is below 2.3.0 or 3.0.0 by inspecting the plugin files or WordPress admin panel. Look for unauthorized user logins or suspicious activity in WordPress logs. Review PayPal callback logs for unexpected requests to the init action with paypal_param parameters.

Impact Analysis

An attacker could exploit this to log in as any user on your WordPress site without credentials, including admin accounts. This results in full control over your site, allowing unauthorized access to sensitive data, modification of content, installation of malicious plugins, or complete site takeover. The vulnerability is triggered by a simple GET request, making it easy to exploit remotely.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR and HIPAA requirements for data protection and access controls. A breach may result in unauthorized exposure of sensitive user information, leading to legal penalties, loss of trust, and compliance violations. Immediate patching is critical to maintain regulatory compliance.

Mitigation Strategies

Immediately update the Divi Membership plugin to version 3.0.0 or later to address the authentication bypass vulnerability. Disable the plugin if an update is not immediately available. Review user accounts for unauthorized access and revoke any suspicious admin privileges. Monitor network traffic for unusual login attempts or PayPal callback interactions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19660. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart