Impact
The Divi Membership plugin for WordPress contains a flaw that lets attackers bypass authentication by sending a crafted GET request with a base64‑encoded paypal_param. The plugin does not validate the parameter, verify PayPal signatures, check ownership, or enforce a nonce before calling wp_set_current_user() and wp_set_auth_cookie(), allowing an attacker to log in as any existing WordPress user, including administrators, and therefore take full control of the site. This is classified as an authentication bypass (CWE‑287).
Affected Systems
All sites running DiviEngine’s Divi Membership plugin up to and including version 2.3.0 are affected. The vulnerability exists regardless of whether PayPal is enabled because the callback hook is registered on every front‑end request.
Risk and Exploitability
The CVSS score of 9.8 signals critical severity, and a lack of an EPSS score indicates that exploitation probability is currently unknown, although the flaw can be exploited immediately by issuing a request to the site with a malicious paypal_param. The vulnerability is not listed in CISA KEV, but an unauthenticated attacker can gain administrative access without any additional steps, enabling full site takeover.
OpenCVE Enrichment