External risk intelligence

WordPress Divi Membership Authentication Bypass Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-19660

The vulnerability exists in a WordPress plugin that is unconditionally registered and active on every front-end request. Because the vulnerable function is part of a public-facing web application and is accessible to unauthenticated users via a GET parameter, it is exposed to the public internet by design in any standard deployment of the affected site.

Authentication Bypass

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects the Divi Membership plugin for WordPress, potentially allowing unauthenticated attackers to bypass security measures and log in as any user, including administrators. This could lead to a complete takeover of the website. The plugin's design means the vulnerability is present on every front-end request, regardless of whether PayPal is configured.

  • Attackers can impersonate any site user.
  • Confirms unauthorized access to sensitive systems.
  • Assess plugin relevance and exposure immediately.

Attack Path

How an attacker could exploit the issue

An attacker can bypass authentication on a WordPress site by exploiting a flaw in the Divi Membership plugin. This flaw allows an unauthenticated attacker to impersonate any existing user, including administrators, by sending a specially crafted GET request. This unauthorized access can lead to a complete takeover of the website.

  • No authentication required.
  • Triggered by a GET parameter.
  • Full site takeover risk.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to bypass authentication and log in as any existing WordPress user, including administrators. This could lead to a full takeover of the affected website when the plugin is installed and the website is accessible via the internet.

  • Website administrative access.
  • Unauthenticated GET parameter manipulation.
  • Full website takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

To address this critical authentication bypass vulnerability in the Divi Membership plugin, the immediate priority for technical leaders and security teams is to identify all WordPress instances using the plugin, confirm their exposure and business criticality, and then coordinate with the accountable application or platform owners. The first practical move involves locating the affected technology, assessing its reachability and importance, and establishing clear ownership for planning and executing remediation, which may involve vendor coordination or temporary risk reduction measures.

  • Application owners should own the issue.
  • Verify plugin reachability and business criticality.
  • Plan remediation based on confirmed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Divi Membership plugin for WordPress?

It is a specialized plugin designed to manage membership subscriptions and restricted content access on WordPress websites. It often integrates with payment gateways like PayPal to handle recurring billing and user account status updates, extending the native functionality of the WordPress user management system.

What does CWE-287 mean for CVE-2026-19660?

CWE-287 identifies an Improper Authentication weakness. In this context, it means the software fails to properly verify the identity of a user before granting access. Because the plugin does not validate cryptographic signatures or check user ownership, it incorrectly trusts information provided by an attacker, allowing them to bypass the login process entirely.

How is this authentication bypass triggered?

An attacker triggers this by sending a specially crafted GET request containing a base64-encoded parameter to the site. Importantly, the vulnerability does not require the PayPal feature to be enabled or configured; the vulnerable code is processed during every front-end request, making the site susceptible even if the plugin's primary payment functions are not in use.

Is my website at risk if it uses this plugin?

According to Halo Surface Signal, this vulnerability is very likely to be reachable. Because the flaw exists in a public-facing web component that is unconditionally active on every request, any WordPress site using this plugin that is accessible via the internet is inherently exposed to unauthorized access attempts.

What should I do if I run this plugin?

Begin by auditing your environment to locate every instance of the Divi Membership plugin. Once identified, evaluate the business criticality of those sites. Prioritize coordination with the teams managing these applications to plan for risk reduction, which may include disabling the plugin until a secure version is available or implementing other temporary safeguards.

References