DiviEngine has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 9.8 (critical), with 2 rated critical.
CVEs per month
Last 12 months, by publish date
1125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/091026/10
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 9.8
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
2
Total CVEs
2
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
DiviEngine vulnerabilities
CVEs affecting DiviEngine, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-19652Critical· 9.8The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0
The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress r…
▾ MidnightDiviEngine · Divi Membershipvia NVD
CVE-2026-19660Critical· 9.8PoCThe Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0
The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET…
▾ AbyssalDiviEngine · Divi MembershipEPSS 0.40%via NVD