{"id":"CVE-2026-19652","title":"The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0","summary":"The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress r…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-269"],"vendor":"DiviEngine","product":"Divi Membership","affected":["divi_membership <= 2.2.0"],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T14:17:10.483","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-19652","references":[{"url":"https://diviengine.com/divi-membership-changelog/","label":"security@wordfence.com"},{"url":"https://diviengine.com/product/divi-membership/","label":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/81d46c7a-dfe4-4991-99cc-66e5c6d3e3c8?source=cve","label":"security@wordfence.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-02T14:20:32.573Z","slug":"CVE-2026-19652","body":"## Overview\n\nThe Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and calling `password_verify()` against an attacker-controlled bcrypt hash supplied in the `form_id` POST parameter, with no validation or whitelist of allowed roles. This makes it possible for unauthenticated attackers to register a new account with the administrator role by submitting a locally computed bcrypt hash of `administrator` as `form_id`, and when `auto_login=on` is submitted, be immediately authenticated as that administrator in the same request, resulting in full site takeover. Exploitation requires a WordPress nonce, but that nonce is publicly emitted on any page rendering the Divi Membership registration form and is therefore obtainable by any unauthenticated visitor.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}