PT-2026-104076 · WordPress · Divi Membership
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Divi Membership versions prior to 2.3.1
Description
An authentication bypass exists in the Divi Membership plugin for WordPress. The
process paypal callback() function, which is linked to the init action, processes a base64-encoded paypal param GET parameter without performing IPN validation, cryptographic signature checks, ownership verification, or nonce validation. This allows an unauthenticated attacker to provide an arbitrary user ID, which is then passed to wp set current user() and wp set auth cookie(), enabling them to log in as any existing user, including administrators, and achieve full site takeover. The issue persists regardless of whether the PayPal gateway is enabled or configured, as the class is instantiated on every front-end request.Recommendations
Update Divi Membership to a version later than 2.3.0.
As a temporary mitigation, restrict access to the
paypal param parameter in GET requests until the plugin is updated.Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Divi Membership