Cyber & AI intelligence
Wasteland.
Briefs indexed2975
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-19660 2026-10-02

Divi Membership WordPress Plugin Flaw Lets Unauthenticated Attackers Log In as Any User (CVE-2026-19660)

"CVE-2026-19660 is a critical (CVSS 9.8) authentication bypass in the Divi Membership plugin for WordPress, versions 2.3.0 and earlier, that lets an unauthenticated attacker log in as any existing user, including…"

CVE-2026-19660 is a critical (CVSS 9.8) authentication bypass in the Divi Membership plugin for WordPress, versions 2.3.0 and earlier, that lets an unauthenticated attacker log in as any existing user, including administrators.

What Is It

The flaw sits in the plugin's process_paypal_callback function, which is hooked to WordPress's init action. The function takes a base64-encoded paypal_param GET parameter and trusts the user ID inside it, with no IPN validation, cryptographic signature check, ownership verification or nonce. That attacker-controlled user ID goes straight to wp_set_current_user() and wp_set_auth_cookie().

The PayPal gateway class is created whether or not PayPal is enabled or configured. As a result, the vulnerable hook is registered on every front-end request, even on sites that never set up PayPal.

The weakness is classified as CWE-287 (Improper Authentication).

Why It Matters

The attack works over the network, takes little effort, and needs no account and no action from a user. An attacker who supplies an administrator's user ID in paypal_param gets a valid authenticated session as that administrator, which per the NVD description means full site takeover. Confidentiality, integrity and availability impacts are all rated High.

This CVE does not appear in CISA's Known Exploited Vulnerabilities (KEV) catalog at the time of writing, so active exploitation has not been confirmed by KEV. The NVD record is marked "Deferred."

What's Vulnerable

Vendor Product Affected Versions
DiviEngine Divi Membership (WordPress plugin) All versions up to and including 2.3.0

Any site running an affected version is exposed, whether or not PayPal is configured.

Patch Status

The NVD record lists all versions through 2.3.0 as affected and links to DiviEngine's Divi Membership changelog. It does not name a specific fixed version. Administrators should:

No CISA KEV required action or due date applies, because the CVE has no KEV entry.

Sources