External risk intelligence

Divi Membership Plugin Privilege Escalation Leading to Site Takeover.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-19652

The vulnerability affects a WordPress plugin designed for public user registration. Such forms are intentionally public-facing by design, allowing unauthenticated visitors to interact with the site, making the vulnerable endpoint accessible to any internet user without requiring prior authentication or administrative access.

Privilege Escalation

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in the Divi Membership WordPress plugin that could allow an unauthenticated attacker to gain administrator privileges and take control of a website. The issue stems from improper handling of user roles during registration, enabling unauthorized users to assign themselves the highest level of access.

  • Unauthenticated users can gain administrator access.
  • Remember this for potential website impact.
  • Confirm if this plugin is used on company sites.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by interacting with the Divi Membership plugin's registration form. The plugin improperly checks user roles when creating new accounts, allowing an attacker to register as an administrator by submitting a specially crafted bcrypt hash. If the plugin is configured for automatic logins, the attacker can gain full administrative control of the website in the same request.

  • No authentication required to access.
  • Submitting a crafted hash to the registration form.
  • Full website takeover via administrator role.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to register an account with administrator privileges on a WordPress site using the Divi Membership plugin. When `auto_login=on` is also submitted, the attacker could gain immediate administrative access to the entire website.

  • User registration data could be compromised.
  • Exploitation may occur over the network.
  • Full website control could result.

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-world ownership for this vulnerability likely falls to the application owner or platform team managing the WordPress instance, in coordination with the security team for exposure assessment and the vendor-management team for plugin updates. The first practical step is to identify all WordPress sites using the Divi Membership plugin, confirm if the affected function is exposed, and then prioritize remediation based on the potential for site takeover.

  • Application owners should manage remediation.
  • Verify plugin presence and exposure.
  • Coordinate vendor update or mitigation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Divi Membership plugin for WordPress?

Divi Membership is a commercial plugin designed for WordPress sites that need to manage user registration, memberships, and content access restrictions. It typically adds specialized forms to a website, allowing visitors to sign up for accounts, purchase access plans, or manage their own profiles directly through the WordPress frontend.

How does CVE-2026-19652 allow privilege escalation?

This vulnerability falls under the weakness class of Improper Privilege Management (CWE-269). It occurs because the plugin trusts user-supplied data to define new account roles. Specifically, the system incorrectly checks if a user should be an administrator by comparing a submitted value against a password hash, allowing an attacker to supply a known hash for the 'administrator' role to bypass security checks during registration.

Do I need to be logged in to trigger this vulnerability?

No. The flaw is accessible to unauthenticated visitors because the registration form is publicly available. Crucially, the vulnerability does not require any pre-existing account access. It only requires the attacker to obtain a publicly visible nonce—a unique token generated by the plugin for the registration form—which is provided to anyone who loads the page.

How relevant is this vulnerability if my site is public?

If your site uses this plugin, Halo Surface Signal flags this as 'Very likely' to be relevant. Because Divi Membership is specifically designed to host public-facing registration forms, the vulnerable endpoint is exposed to the internet by design. This means any remote user can interact with the plugin's internal logic without needing special network positioning.

What is the first step to address CVE-2026-19652?

Begin by auditing your WordPress environment to inventory every site running the Divi Membership plugin. Once identified, confirm the specific version in use. If you are on version 2.2.0 or older, you should immediately check the official vendor changelog for security updates and coordinate with your site administrators to apply patches or disable the registration functionality until the software is secured.

References