Sceawere

Vulnerability Detail

CVE-2026-19660UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Divi Membership Authentication Bypass

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
18h ago
Vendor
DiviEngine
Product
Divi Membership
Attack Type
CWE-287 Improper Authentication
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature check, no ownership verification, and no nonce, allowing it to trust an entirely attacker-controlled user ID value that is passed directly to `wp_set_current_user()` and `wp_set_auth_cookie()`. This makes it possible for unauthenticated attackers to log in as any existing WordPress user — including administrators — by supplying an arbitrary user ID in the `paypal_param` GET parameter, resulting in full site takeover. The vulnerability is further compounded by the fact that the PayPal gateway class is instantiated unconditionally regardless of whether PayPal is enabled or configured, ensuring the vulnerable hook is always registered on every front-end request.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-10-02T05:16:38.430Z",
  "pubdate": "2026-10-02T05:16:38.430Z",
  "executiveSummary": "The Divi Membership plugin for WordPress, in versions up to and including 2.3.0, contains a critical authentication bypass vulnerability. This flaw allows unauthenticated attackers to masquerade as any user, including site administrators, by manipulating the 'paypal_param' GET parameter.\nThe vulnerability stems from insecure processing of callback parameters during the PayPal IPN handling process. Specifically, the plugin fails to implement essential validation mechanisms such as cryptographic signatures, nonce verification, or ownership authentication.\nBecause the vulnerable 'process_paypal_callback' function is attached to the 'init' hook and executed unconditionally on every request, the attack surface is globally exposed across the entire WordPress instance. Successful exploitation grants an attacker full control over the target WordPress installation, enabling unauthorized data access, configuration modification, and complete site compromise.\nThe absence of IPN validation means an attacker does not need a legitimate PayPal interaction to trigger the session creation. This requires zero prior authentication, posing a severe risk to any WordPress environment utilizing the plugin. Remediation is mandatory, as this flaw provides a trivial path to total administrative takeover.",
  "technicalDetails": "The root cause of this vulnerability is the improper implementation of the 'process_paypal_callback' function within the Divi Membership plugin. This function, which is designed to handle PayPal Instant Payment Notification (IPN) callbacks, is bound to the 'init' action hook. This architecture ensures that the logic is executed on every page load, regardless of whether the PayPal gateway functionality is active or correctly configured.\nThe function expects a 'paypal_param' GET parameter, which is intended to be a base64-encoded string containing PayPal transaction details. However, the plugin fails to perform any verification on this input. It does not validate the integrity of the data using cryptographic signatures, verify the authenticity of the sender via IPN validation, or confirm the request's legitimacy via a WordPress nonce. Furthermore, there is no ownership verification implemented to ensure the user ID provided within the payload correlates with a legitimate payment event.\nUpon receiving the 'paypal_param' input, the function decodes the base64 string and directly parses the contained user ID. This value is then passed into 'wp_set_current_user()' and 'wp_set_auth_cookie()'. Because these functions are designed to establish an authenticated session for the specified user ID, the plugin inadvertently grants the attacker the ability to spoof any user on the platform. By crafting a base64 string containing the User ID '1' (the default administrator account in WordPress), an attacker can successfully authenticate as the site administrator without providing valid credentials.\nThe attack flow is as follows: 1) An unauthenticated attacker identifies a target site running Divi Membership <= 2.3.0. 2) The attacker crafts a payload containing the target user ID, encodes it into base64, and appends it to a request as the 'paypal_param' GET parameter. 3) The 'init' hook fires, executing the vulnerable 'process_paypal_callback' function. 4) The plugin blindly accepts the user ID from the parameter and calls 'wp_set_auth_cookie()', effectively setting the session cookie for the attacker. 5) The attacker is now logged in with the privileges of the targeted user ID. Post-exploitation impact is catastrophic, as the attacker gains full administrative access to the WordPress dashboard, allowing them to install malicious plugins, modify site content, or exfiltrate sensitive database information."
}
CVE-2026-19660: Divi Membership Authentication Bypass (CRITICAL Severity, CVSS: 9.8) | Sceawere