CVE-2026-19660

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature check, no ownership verification, and no nonce, allowing it to trust an entirely attacker-controlled user ID value that is passed directly to `wp_set_current_user()` and `wp_set_auth_cookie()`. This makes it possible for unauthenticated attackers to log in as any existing WordPress user — including administrators — by supplying an arbitrary user ID in the `paypal_param` GET parameter, resulting in full site takeover. The vulnerability is further compounded by the fact that the PayPal gateway class is instantiated unconditionally regardless of whether PayPal is enabled or configured, ensuring the vulnerable hook is always registered on every front-end request.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-10-02: 210-02
Referenced assets1 URL
By indicator
Full discourse2 posts
  • mürrez@murrezsec

    🚨 CVE-2026-19660 — Divi Membership ≤2.3.0 Critical unauthenticated auth bypass via paypal_param, potentially enabling arbitrary WordPress user login. 🔴 CVSS 9.8 Critical PoC: https://pocbit.org/pocs/cve-2026-19660 #CVE #WordPress #Divi #CyberSecurity #InfoSec #PoC

    0002172
    629 followersView on X
  • Atlas Threat Monitoring@ThreatAtlas

    Unpatched vulnerabilities don't stay hidden on our atlas. #CVE CRITICAL VULNERABILITY DETECTED CVE ID → CVE-2026-19660 Vendor → Unknown Severity → Critical — CVSS 9.8 Product → Unknown Date → 2026-10-02 A critical vulnerability (Improper Authentication) has been disclosed affecting Unknown. Patch immediately. Powered by @Brandefense #ThreatIntel #CyberSecurity #CVE #Unknown

    0000049
    434 followersView on X

Explore more