PT-2026-104076 · WordPress · Divi Membership

·

CVE-2026-19660

·

Published

2026-10-02

·

Updated

2026-10-02

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Divi Membership versions prior to 2.3.1
Description An authentication bypass exists in the Divi Membership plugin for WordPress. The process paypal callback() function, which is linked to the init action, processes a base64-encoded paypal param GET parameter without performing IPN validation, cryptographic signature checks, ownership verification, or nonce validation. This allows an unauthenticated attacker to provide an arbitrary user ID, which is then passed to wp set current user() and wp set auth cookie(), enabling them to log in as any existing user, including administrators, and achieve full site takeover. The issue persists regardless of whether the PayPal gateway is enabled or configured, as the class is instantiated on every front-end request.
Recommendations Update Divi Membership to a version later than 2.3.0. As a temporary mitigation, restrict access to the paypal param parameter in GET requests until the plugin is updated.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19660

Affected Products

Divi Membership