CRITICAL 9.8 NVD
CVE-2026-19652
The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_han
The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and calling `password_verify()` against an attacker-controlled bcrypt hash supplied in the `form_id` POST parameter, with no validation or whitelist of allowed roles. This makes it possible for unauthenticated attackers to register a new account with the administrator role by submitting a locally computed bcrypt hash of `administrator` as `form_id`, and when `auto_login=on` is submitted, be immediately authenticated as that administrator in the same request, resulting in full site takeover. Exploitation requires a WordPress nonce, but that nonce is publicly emitted on any page rendering the Divi Membership registration form and is therefore obtainable by any unauthenticated visitor.
References
- https://diviengine.com/divi-membership-changelog/
- https://diviengine.com/product/divi-membership/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/81d46c7a-dfe4-4991-99cc-66e5c6d3
This critical severity vulnerability with a CVSS score of 9.8 was published on 2026-10-02 via NVD.
Risk Timeline
CVE Disclosed2026-10-02 · -1 days ago
Remediation Resources
Analysis & PoC
diviengine.com/divi-membership-changelog/Analysis & PoC
diviengine.com/product/divi-membership/
vulnfeed aggregates 10476 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.