---
id: CVE-2026-19652
title: >-
  The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation
  in versions up to, and including, 2.2.0
summary: >-
  The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation
  in versions up to, and including, 2.2.0. This is due to the
  `dmem_form_submit_handler()` function determining the new user's role by
  iterating all WordPress r…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-269
vendor: DiviEngine
product: Divi Membership
affected:
  - divi_membership <= 2.2.0
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T14:17:10.483'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19652'
references:
  - url: 'https://diviengine.com/divi-membership-changelog/'
    label: security@wordfence.com
  - url: 'https://diviengine.com/product/divi-membership/'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/81d46c7a-dfe4-4991-99cc-66e5c6d3e3c8?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-02T14:20:32.573Z'
---

## Overview

The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and calling `password_verify()` against an attacker-controlled bcrypt hash supplied in the `form_id` POST parameter, with no validation or whitelist of allowed roles. This makes it possible for unauthenticated attackers to register a new account with the administrator role by submitting a locally computed bcrypt hash of `administrator` as `form_id`, and when `auto_login=on` is submitted, be immediately authenticated as that administrator in the same request, resulting in full site takeover. Exploitation requires a WordPress nonce, but that nonce is publicly emitted on any page rendering the Divi Membership registration form and is therefore obtainable by any unauthenticated visitor.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
