๐Ÿ” CVE Alert

CVE-2026-19660

CRITICAL 9.8

Divi Membership <= 2.3.0 - Unauthenticated Authentication Bypass via 'paypal_param' Parameter

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature check, no ownership verification, and no nonce, allowing it to trust an entirely attacker-controlled user ID value that is passed directly to `wp_set_current_user()` and `wp_set_auth_cookie()`. This makes it possible for unauthenticated attackers to log in as any existing WordPress user โ€” including administrators โ€” by supplying an arbitrary user ID in the `paypal_param` GET parameter, resulting in full site takeover. The vulnerability is further compounded by the fact that the PayPal gateway class is instantiated unconditionally regardless of whether PayPal is enabled or configured, ensuring the vulnerable hook is always registered on every front-end request.

CWE CWE-287
Vendor diviengine
Product divi membership
Published Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for diviengine divi membership

Be the first to know when new critical vulnerabilities affecting diviengine divi membership are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

DiviEngine / Divi Membership
0 โ‰ค 2.3.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/3d650cda-341f-4772-9b67-1bac200e3fb7?source=cve diviengine.com: https://diviengine.com/divi-membership-changelog/

Credits

0xd4rk5id3