Sceawere

Vulnerability Detail

CVE-2026-19652UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Divi Membership Privilege Escalation

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
9h ago
Vendor
DiviEngine
Product
Divi Membership
Attack Type
CWE-269 Improper Privilege Management
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and calling `password_verify()` against an attacker-controlled bcrypt hash supplied in the `form_id` POST parameter, with no validation or whitelist of allowed roles. This makes it possible for unauthenticated attackers to register a new account with the administrator role by submitting a locally computed bcrypt hash of `administrator` as `form_id`, and when `auto_login=on` is submitted, be immediately authenticated as that administrator in the same request, resulting in full site takeover. Exploitation requires a WordPress nonce, but that nonce is publicly emitted on any page rendering the Divi Membership registration form and is therefore obtainable by any unauthenticated visitor.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-10-02T14:17:10.483Z",
  "pubdate": "2026-10-02T14:17:10.483Z",
  "executiveSummary": "The Divi Membership plugin for WordPress, in versions up to and including 2.2.0, contains a critical privilege escalation vulnerability. The flaw resides within the user registration process, allowing unauthenticated attackers to register new accounts with arbitrary privileges, including the administrator role. This vulnerability stems from improper validation of role-assignment parameters during account creation.\nBy manipulating the form submission process, an attacker can bypass standard security controls and gain full administrative access to the WordPress environment. Successful exploitation results in a complete site takeover. The attack vector is reachable by any unauthenticated visitor, provided they can obtain a public nonce, which is natively exposed on pages containing the plugin's registration form. Due to the ease of exploitation and the severity of the potential impact—ranging from total site compromise to arbitrary code execution via administrative features—this vulnerability is classified as critical. Organizations utilizing this plugin must treat this as a high-priority security incident.",
  "technicalDetails": "The vulnerability is located in the dmem_form_submit_handler() function within the Divi Membership plugin. This function is responsible for processing registration requests and dynamically determining the user's role. The logic incorrectly iterates through all registered WordPress roles and uses password_verify() to compare the user-supplied form_id POST parameter against a bcrypt hash of the role name.\nThe root cause is a lack of server-side validation or a strict whitelist for role assignment. Instead of validating the form_id against a predefined set of allowed roles, the plugin trusts the user input to dictate the permission level. An attacker can perform a local computation of a bcrypt hash corresponding to the string 'administrator'. By submitting this hash as the form_id parameter in a registration request, the attacker triggers a successful match within the dmem_form_submit_handler() function.\nThe attack flow proceeds as follows: 1) The attacker navigates to a publicly accessible page containing the Divi Membership registration form to extract a valid WordPress nonce. 2) The attacker crafts an HTTP POST request targeting the registration endpoint, including the valid nonce, the computed bcrypt hash of the 'administrator' role in the form_id field, and sets the auto_login parameter to 'on'. 3) The server receives the request, processes the user creation, and the dmem_form_submit_handler() function successfully verifies the hash, incorrectly elevating the newly created account to the administrator level. 4) Because auto_login is enabled, the server immediately authenticates the attacker as the newly created administrator in the same request cycle.\nThis exploitation method requires no prior authentication or administrative privileges, as the nonce is public and the registration logic fails to verify the requestor's authorization level. The impact of this post-exploitation behavior is total system compromise, allowing the attacker to execute arbitrary administrative actions, modify plugin settings, alter site content, or install malicious software, effectively leading to a full site takeover."
}
CVE-2026-19652: Divi Membership Privilege Escalation (CRITICAL Severity, CVSS: 9.8) | Sceawere