Diviengine Divi Membership vulnerabilities
2 known vulnerabilities affecting diviengine/divi_membership.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2
Vulnerabilities
Page 1 of 1
CVE-2026-19660P2CRITICALCVSS 9.8≤ 2.3.02026-10-02
CVE-2026-19660 [CRITICAL] CWE-287 CVE-2026-19660: The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up t
The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature check, no ownership verification, and no nonce, al
nvd
CVE-2026-19652P2CRITICALCVSS 9.8≤ 2.2.02026-10-02
CVE-2026-19652 [CRITICAL] CWE-269 CVE-2026-19652: The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, an
The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and calling `password_verify()` against an attacker-controlled bcrypt hash supplied in the `form_id` POST p
nvd