Executive Summary
A critical authentication bypass vulnerability (CVE-2026-19660) has been disclosed in the Divi Membership plugin for WordPress, developed by DiviEngine. The vulnerability carries a CVSS score of 9.8 and affects all versions up to and including 2.3.0.
CVSS Score: 9.8 (Critical)
The flaw lives in the plugin's process_paypal_callback function, which is hooked to WordPress's init action and runs on every front-end request — regardless of whether the site even uses PayPal. The function accepts a base64-encoded paypal_param GET parameter and trusts it outright: no IPN (Instant Payment Notification) validation, no cryptographic signature check, no ownership verification, and no nonce. An attacker can forge this parameter to supply an arbitrary WordPress user ID, which the plugin then passes directly into wp_set_current_user() and wp_set_auth_cookie() — logging the attacker in as that user with no credentials whatsoever. Because the user ID is fully attacker-controlled, the target can be an administrator, resulting in full site takeover. A patch is available in version 3.0.0.
This disclosure landed alongside three other unrelated WordPress plugins (DevKit Pro, JSON API Auth, and WPMobile.App) that each published their own CVSS 9.8 unauthenticated admin-takeover flaw the same day — a notable cluster, though each bug has a distinct, unrelated root cause.
Vulnerability Overview
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-19660 |
| CVSS Score | 9.8 (Critical) |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CWE | CWE-287 (Improper Authentication) |
| Type | Unauthenticated Authentication Bypass / Account Takeover |
| Attack Vector | Network (no authentication required) |
| Privileges Required | None |
| User Interaction | None |
| Vulnerable Function | process_paypal_callback(), hooked to init |
| Vendor | DiviEngine |
Affected Versions
| Plugin | Affected Versions | Fixed Version |
|---|---|---|
| Divi Membership | ≤ 2.3.0 | 3.0.0 |
How It Works
Root Cause: An Unvalidated Trust Boundary
The PayPal payment-gateway class inside Divi Membership is instantiated unconditionally on every page load, regardless of whether the site administrator has enabled or configured PayPal at all. This guarantees that the vulnerable init hook — process_paypal_callback — is always registered and reachable on the live site.
Attack Vector
1. Attacker identifies a WordPress site running Divi Membership ≤ 2.3.0
2. Attacker base64-encodes a crafted payload containing an arbitrary target user ID
3. Attacker sends a GET request with the forged value in the `paypal_param` parameter
4. process_paypal_callback() decodes the parameter with no IPN check, no signature
verification, no ownership check, and no nonce
5. The attacker-controlled user ID is passed directly to wp_set_current_user()
and wp_set_auth_cookie()
6. The attacker's browser receives a valid authenticated session cookie for
the targeted account — including administrator accounts
7. Full site takeover: plugin/theme installation, database access, content
and user manipulationImpact of Successful Exploitation
| Impact Area | Description |
|---|---|
| Account Takeover | Attacker logs in as any existing user by supplying that user's ID |
| Administrator Compromise | Targeting an admin user ID grants full wp-admin control |
| Full Site Takeover | Malicious plugin/theme upload, arbitrary PHP execution via admin tools |
| Data Exposure | Access to member data, orders, and any content gated behind membership |
| Persistence | Attacker can create new administrator accounts or rotate credentials |
| Trust Abuse | Exploit requires no interaction from the victim and no valid PayPal transaction |
Recommendations
For Site Administrators
- Update Divi Membership to version 3.0.0 or later immediately. Via WordPress admin: Plugins → Installed Plugins → Divi Membership → Update Now, or via WP-CLI:
wp plugin update divi-membership wp plugin get divi-membership --field=version - If immediate patching is not possible, deactivate the Divi Membership plugin entirely until the update can be applied — there is no safe partial mitigation, since the vulnerable hook fires regardless of PayPal configuration.
- Audit administrator and privileged accounts created or modified around the disclosure window for anything unrecognized.
- Force-rotate session tokens by having all users log out, and consider rotating WordPress security keys/salts (
wp config shuffle-salts) if compromise is suspected.
For Security Teams
- Review access logs for GET requests containing a
paypal_paramparameter, particularly ones with unusually long or non-standard base64 payloads. - Check for unexpected administrator logins with no corresponding legitimate PayPal transaction or login form submission.
- Deploy a WAF rule to block or flag requests to front-end URLs carrying a
paypal_paramparameter where PayPal is not an enabled payment method. - Add Divi Membership to patch-priority tracking given the CVSS 9.8 rating and trivial, unauthenticated exploitation path.
For End Users / Site Owners
- If you run a membership site on Divi Membership, check your installed version now and update before taking any other action.
- Review recent member and administrator account activity for anything you don't recognize.
- Change passwords for admin-level accounts as a precaution after patching, particularly if the site was running a vulnerable version for an extended period.
Key Takeaways
- CVE-2026-19660 is a pre-authentication, full account-takeover vulnerability in the Divi Membership WordPress plugin, rated CVSS 9.8 (Critical).
- The root cause is a complete absence of validation — no IPN check, no signature, no ownership verification, no nonce — on a base64-encoded
paypal_paramGET parameter that controls which WordPress user ID gets logged in. - The vulnerable code path is always reachable, because the PayPal gateway class loads unconditionally whether or not PayPal is configured on the site.
- Exploitation requires no credentials and no user interaction, and can directly target administrator accounts.
- Divi Membership 3.0.0 contains the fix — sites on version 2.3.0 or earlier should update immediately.
- This CVE was disclosed as part of a same-day cluster of four unrelated CVSS 9.8 WordPress plugin authentication-bypass flaws, underscoring the value of routine plugin inventory and patch-priority review.
Sources
- NVD — CVE-2026-19660
- Strix — CVE-2026-19660: Divi Membership Authentication Bypass (CVSS 9.8)
- DEV Community — WordPress Auth Bypass Cluster: 4x CVSS 9.8, Full Site Takeover via Plugin Flaws