CVE-2026-19660 is a critical (CVSS 9.8) authentication bypass in the Divi Membership plugin for WordPress, versions 2.3.0 and earlier, that lets an unauthenticated attacker log in as any existing user, including administrators.
What Is It
The flaw sits in the plugin's process_paypal_callback function, which is hooked to WordPress's init action. The function takes a base64-encoded paypal_param GET parameter and trusts the user ID inside it, with no IPN validation, cryptographic signature check, ownership verification or nonce. That attacker-controlled user ID goes straight to wp_set_current_user() and wp_set_auth_cookie().
The PayPal gateway class is created whether or not PayPal is enabled or configured. As a result, the vulnerable hook is registered on every front-end request, even on sites that never set up PayPal.
The weakness is classified as CWE-287 (Improper Authentication).
Why It Matters
- CVSS 3.1 score: 9.8 (CRITICAL)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The attack works over the network, takes little effort, and needs no account and no action from a user. An attacker who supplies an administrator's user ID in paypal_param gets a valid authenticated session as that administrator, which per the NVD description means full site takeover. Confidentiality, integrity and availability impacts are all rated High.
This CVE does not appear in CISA's Known Exploited Vulnerabilities (KEV) catalog at the time of writing, so active exploitation has not been confirmed by KEV. The NVD record is marked "Deferred."
What's Vulnerable
| Vendor | Product | Affected Versions |
|---|---|---|
| DiviEngine | Divi Membership (WordPress plugin) | All versions up to and including 2.3.0 |
Any site running an affected version is exposed, whether or not PayPal is configured.
Patch Status
The NVD record lists all versions through 2.3.0 as affected and links to DiviEngine's Divi Membership changelog. It does not name a specific fixed version. Administrators should:
- Check the vendor changelog for a release that addresses this issue and update to it.
- If no fixed release is available, consider disabling the plugin until one is.
- Since successful exploitation grants administrator sessions, review sites that ran affected versions for unexpected administrator activity.
No CISA KEV required action or due date applies, because the CVE has no KEV entry.