Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a critical vulnerability in the Divi Membership WordPress plugin that could allow an unauthenticated attacker to gain administrator privileges and take control of a website. The issue stems from improper handling of user roles during registration, enabling unauthorized users to assign themselves the highest level of access.
- Unauthenticated users can gain administrator access.
- Remember this for potential website impact.
- Confirm if this plugin is used on company sites.
Attack Path
How an attacker could exploit the issue
An attacker can exploit this vulnerability by interacting with the Divi Membership plugin's registration form. The plugin improperly checks user roles when creating new accounts, allowing an attacker to register as an administrator by submitting a specially crafted bcrypt hash. If the plugin is configured for automatic logins, the attacker can gain full administrative control of the website in the same request.
- No authentication required to access.
- Submitting a crafted hash to the registration form.
- Full website takeover via administrator role.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow an unauthenticated attacker to register an account with administrator privileges on a WordPress site using the Divi Membership plugin. When `auto_login=on` is also submitted, the attacker could gain immediate administrative access to the entire website.
- User registration data could be compromised.
- Exploitation may occur over the network.
- Full website control could result.
Operational Fix
Recommended remediation, mitigation, and detection steps
Real-world ownership for this vulnerability likely falls to the application owner or platform team managing the WordPress instance, in coordination with the security team for exposure assessment and the vendor-management team for plugin updates. The first practical step is to identify all WordPress sites using the Divi Membership plugin, confirm if the affected function is exposed, and then prioritize remediation based on the potential for site takeover.
- Application owners should manage remediation.
- Verify plugin presence and exposure.
- Coordinate vendor update or mitigation.