Divi Membership CVE-2026-19660 (CVSS 9.8): unauth auth bypass via paypal_param → any-user login/admin takeover ≤2.3.0; no fix yet
Wordfence CNA CVE-2026-19660 (published 2 October 2026; disclosed 1 Oct; CVSS 3.1 9.8 Critical AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): unauthenticated authentication bypass in DiviEngine’s Divi Membership WordPress plugin through 2.3.0. The process_paypal_callback function (hooked to init) accepts a base64-encoded paypal_param GET value with no PayPal IPN validation, signature check, ownership check, or nonce, then passes an attacker-controlled user ID to wp_set_current_user() / wp_set_auth_cookie() — full site takeover including administrators. The PayPal gateway class is instantiated on every front-end request even when PayPal is not enabled, so the hook is always registered. Finder credit: 0xd4rk5id3. Divi Engine changelog still lists 2.3.0 (1 Sep 2026) as newest at desk check — no patched release documented. Primary: CVE.org / Wordfence CNA; vendor changelog reference.
- Product
- WordPress plugin: Divi Membership (DiviEngine)
- Versions
- Affected: all versions ≤ 2.3.0 (semver). Fixed: not documented at 16:00 Perth 2 Oct 2026 desk check (changelog newest still 2.3.0).
- CVSS
- (CVSS 3.1 Critical; Wordfence)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Until Divi Engine ships a release >2.3.0 that removes/hardens process_paypal_callback: disable or remove Divi Membership on internet-facing WordPress; hunt unexpected admin sessions / auth cookies issued without login; monitor for paypal_param query abuse. Do not invent a patch floor — none published yet.
Primary: CVE.org / Wordfence CNA — CVE-2026-19660 Divi Membership unauth auth bypass · Vendor: Divi Engine — Divi Membership changelog (2.3.0 newest listed; no fix noted) · CVE: CVE-2026-19660 · Wordfence threat-intel — CVE-2026-19660 vulnerability record
