Description
The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature check, no ownership verification, and no nonce, allowing it to trust an entirely attacker-controlled user ID value that is passed directly to `wp_set_current_user()` and `wp_set_auth_cookie()`. This makes it possible for unauthenticated attackers to log in as any existing WordPress user — including administrators — by supplying an arbitrary user ID in the `paypal_param` GET parameter, resulting in full site takeover. The vulnerability is further compounded by the fact that the PayPal gateway class is instantiated unconditionally regardless of whether PayPal is enabled or configured, ensuring the vulnerable hook is always registered on every front-end request.
Published: 2026-10-02
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Authentication Bypass
Action: Immediate Patch
AI Analysis

Impact

The Divi Membership plugin for WordPress contains a flaw that lets attackers bypass authentication by sending a crafted GET request with a base64‑encoded paypal_param. The plugin does not validate the parameter, verify PayPal signatures, check ownership, or enforce a nonce before calling wp_set_current_user() and wp_set_auth_cookie(), allowing an attacker to log in as any existing WordPress user, including administrators, and therefore take full control of the site. This is classified as an authentication bypass (CWE‑287).

Affected Systems

All sites running DiviEngine’s Divi Membership plugin up to and including version 2.3.0 are affected. The vulnerability exists regardless of whether PayPal is enabled because the callback hook is registered on every front‑end request.

Risk and Exploitability

The CVSS score of 9.8 signals critical severity, and a lack of an EPSS score indicates that exploitation probability is currently unknown, although the flaw can be exploited immediately by issuing a request to the site with a malicious paypal_param. The vulnerability is not listed in CISA KEV, but an unauthenticated attacker can gain administrative access without any additional steps, enabling full site takeover.

Generated by OpenCVE AI on October 2, 2026 at 05:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Divi Membership to the latest version, which removes the vulnerable hook.
  • If an upgrade cannot be performed, disable the PayPal gateway or remove the process_paypal_callback hook so that unauthenticated requests cannot trigger credential creation.
  • Monitor login events and consider restricting the callback to legitimate PayPal IP addresses or adding a secret parameter to mitigate the risk while awaiting a patch.

Generated by OpenCVE AI on October 2, 2026 at 05:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 04:45:00 +0000

Type Values Removed Values Added
Description The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature check, no ownership verification, and no nonce, allowing it to trust an entirely attacker-controlled user ID value that is passed directly to `wp_set_current_user()` and `wp_set_auth_cookie()`. This makes it possible for unauthenticated attackers to log in as any existing WordPress user — including administrators — by supplying an arbitrary user ID in the `paypal_param` GET parameter, resulting in full site takeover. The vulnerability is further compounded by the fact that the PayPal gateway class is instantiated unconditionally regardless of whether PayPal is enabled or configured, ensuring the vulnerable hook is always registered on every front-end request.
Title Divi Membership <= 2.3.0 - Unauthenticated Authentication Bypass via 'paypal_param' Parameter
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-02T04:27:11.341Z

Reserved: 2026-08-12T20:11:51.671Z

Link: CVE-2026-19660

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T05:16:38.430

Modified: 2026-10-02T05:16:38.430

Link: CVE-2026-19660

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T05:30:17Z

Weaknesses