SECURITYCRITICALCVE-2026-19660

Critical Auth Bypass in Divi Membership Lets Attackers Log In as Any User

CVE-2026-19660 (CVSS 9.8): a forged paypal_param GET request lets unauthenticated attackers log in as any WordPress user, including admins.

Dylan H.

Security Team

October 2, 2026
6 min read
Critical Auth Bypass in Divi Membership Lets Attackers Log In as Any User

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • Divi Membership Plugin ≤ 2.3.0

Executive Summary

A critical authentication bypass vulnerability (CVE-2026-19660) has been disclosed in the Divi Membership plugin for WordPress, developed by DiviEngine. The vulnerability carries a CVSS score of 9.8 and affects all versions up to and including 2.3.0.

CVSS Score: 9.8 (Critical)

The flaw lives in the plugin's process_paypal_callback function, which is hooked to WordPress's init action and runs on every front-end request — regardless of whether the site even uses PayPal. The function accepts a base64-encoded paypal_param GET parameter and trusts it outright: no IPN (Instant Payment Notification) validation, no cryptographic signature check, no ownership verification, and no nonce. An attacker can forge this parameter to supply an arbitrary WordPress user ID, which the plugin then passes directly into wp_set_current_user() and wp_set_auth_cookie() — logging the attacker in as that user with no credentials whatsoever. Because the user ID is fully attacker-controlled, the target can be an administrator, resulting in full site takeover. A patch is available in version 3.0.0.

This disclosure landed alongside three other unrelated WordPress plugins (DevKit Pro, JSON API Auth, and WPMobile.App) that each published their own CVSS 9.8 unauthenticated admin-takeover flaw the same day — a notable cluster, though each bug has a distinct, unrelated root cause.


Vulnerability Overview

AttributeValue
CVE IDCVE-2026-19660
CVSS Score9.8 (Critical)
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWECWE-287 (Improper Authentication)
TypeUnauthenticated Authentication Bypass / Account Takeover
Attack VectorNetwork (no authentication required)
Privileges RequiredNone
User InteractionNone
Vulnerable Functionprocess_paypal_callback(), hooked to init
VendorDiviEngine

Affected Versions

PluginAffected VersionsFixed Version
Divi Membership≤ 2.3.03.0.0

How It Works

Root Cause: An Unvalidated Trust Boundary

The PayPal payment-gateway class inside Divi Membership is instantiated unconditionally on every page load, regardless of whether the site administrator has enabled or configured PayPal at all. This guarantees that the vulnerable init hook — process_paypal_callback — is always registered and reachable on the live site.

Attack Vector

1. Attacker identifies a WordPress site running Divi Membership ≤ 2.3.0
2. Attacker base64-encodes a crafted payload containing an arbitrary target user ID
3. Attacker sends a GET request with the forged value in the `paypal_param` parameter
4. process_paypal_callback() decodes the parameter with no IPN check, no signature
   verification, no ownership check, and no nonce
5. The attacker-controlled user ID is passed directly to wp_set_current_user()
   and wp_set_auth_cookie()
6. The attacker's browser receives a valid authenticated session cookie for
   the targeted account — including administrator accounts
7. Full site takeover: plugin/theme installation, database access, content
   and user manipulation

Impact of Successful Exploitation

Impact AreaDescription
Account TakeoverAttacker logs in as any existing user by supplying that user's ID
Administrator CompromiseTargeting an admin user ID grants full wp-admin control
Full Site TakeoverMalicious plugin/theme upload, arbitrary PHP execution via admin tools
Data ExposureAccess to member data, orders, and any content gated behind membership
PersistenceAttacker can create new administrator accounts or rotate credentials
Trust AbuseExploit requires no interaction from the victim and no valid PayPal transaction

Recommendations

For Site Administrators

  1. Update Divi Membership to version 3.0.0 or later immediately. Via WordPress admin: Plugins → Installed Plugins → Divi Membership → Update Now, or via WP-CLI:
    wp plugin update divi-membership
    wp plugin get divi-membership --field=version
  2. If immediate patching is not possible, deactivate the Divi Membership plugin entirely until the update can be applied — there is no safe partial mitigation, since the vulnerable hook fires regardless of PayPal configuration.
  3. Audit administrator and privileged accounts created or modified around the disclosure window for anything unrecognized.
  4. Force-rotate session tokens by having all users log out, and consider rotating WordPress security keys/salts (wp config shuffle-salts) if compromise is suspected.

For Security Teams

  1. Review access logs for GET requests containing a paypal_param parameter, particularly ones with unusually long or non-standard base64 payloads.
  2. Check for unexpected administrator logins with no corresponding legitimate PayPal transaction or login form submission.
  3. Deploy a WAF rule to block or flag requests to front-end URLs carrying a paypal_param parameter where PayPal is not an enabled payment method.
  4. Add Divi Membership to patch-priority tracking given the CVSS 9.8 rating and trivial, unauthenticated exploitation path.

For End Users / Site Owners

  1. If you run a membership site on Divi Membership, check your installed version now and update before taking any other action.
  2. Review recent member and administrator account activity for anything you don't recognize.
  3. Change passwords for admin-level accounts as a precaution after patching, particularly if the site was running a vulnerable version for an extended period.

Key Takeaways

  1. CVE-2026-19660 is a pre-authentication, full account-takeover vulnerability in the Divi Membership WordPress plugin, rated CVSS 9.8 (Critical).
  2. The root cause is a complete absence of validation — no IPN check, no signature, no ownership verification, no nonce — on a base64-encoded paypal_param GET parameter that controls which WordPress user ID gets logged in.
  3. The vulnerable code path is always reachable, because the PayPal gateway class loads unconditionally whether or not PayPal is configured on the site.
  4. Exploitation requires no credentials and no user interaction, and can directly target administrator accounts.
  5. Divi Membership 3.0.0 contains the fix — sites on version 2.3.0 or earlier should update immediately.
  6. This CVE was disclosed as part of a same-day cluster of four unrelated CVSS 9.8 WordPress plugin authentication-bypass flaws, underscoring the value of routine plugin inventory and patch-priority review.

Sources