Divi Membership paypal_param Bypass (CVE-2026-19660): Fake PayPal, Real Admin Cookies
Admin · October 2, 2026 · 7 views
Divi Membership and the fake PayPal callback
Divi Membership by DiviEngine powers paid membership sites on Divi: plans, Stripe/PayPal, trials, and gated content. CVE-2026-19660 (CWE-287 Improper Authentication, CVSS 3.1 9.8 Critical) affects ≤ 2.3.0: an init hook handler process_paypal_callback trusts a base64 paypal_param GET value without PayPal IPN validation, signature verification, or membership ownership checks—then calls wp_set_current_user() and wp_set_auth_cookie() for an attacker-chosen user ID.
Catalog and tooling: CVE-2026-19660 on pocbit.org. Repository: murrez/CVE-2026-19660.
Why this hits even “PayPal disabled” shops
Reports emphasize that the PayPal gateway class may be constructed on every front-end request, even when PayPal is not configured or enabled. That means the vulnerable init path can exist without merchants consciously turning on PayPal—membership sites using Stripe-only billing may still be exposed until patched.
Impact: login as any existing WordPress user, including administrators, via a crafted query string—full site takeover without wp-login noise.
Defender checklist
| # | Action | Detail |
|---|--------|--------|
| 1 | Inventory Divi Membership version | License portal / plugin header; compare to > 2.3.0 |
| 2 | Upgrade immediately | Divi Membership changelog |
| 3 | Search logs for paypal_param= on anonymous GETs | Especially before new wordpress_logged_in_* cookies |
| 4 | Invalidate admin sessions after upgrade | Assume compromise if suspicious params appeared |
| 5 | Restrict /wp-admin/ by IP during maintenance | Bridge control only |
Pair with how to prioritize critical CVEs and WordPress security checklist (2026).
Not the same as other “PayPal webhook” CVEs
WordPress ecosystem sees multiple PayPal-adjacent bugs (webhook signature bypass on other membership plugins, etc.). CVE-2026-19660 is specific to DiviEngine’s paypal_param callback on init—WAF and detection rules must match this parameter name and encoding, not generic PayPal paths.
Detection hints (your assets only)
Membership stacks on Divi often expose registration/checkout pages and DiviEngine branding. Hunt your own estates for Divi Membership plugin paths and version markers—use results for ticketing, not third-party probing.
Patch validation in a lab
- Licensed lab install with Divi Membership ≤ 2.3.0.
- Run public PoC check mode, then authorized exploit against the lab host.
- Upgrade beyond 2.3.0; confirm callback no longer mints sessions for forged params.
See safe PoC lab setup.
FAQ
We only use Stripe—skip the patch?
No. Upgrade based on vendor fixed version; do not assume payment UI reflects which hooks are registered.
Is base64 in query strings enough to WAF-block?
Temporary rule on paypal_param helps during rollout; vendor fix removes the trust boundary failure.
Bottom line
CVE-2026-19660 shows that any code path that sets auth cookies must validate payment reality, not attacker-supplied identifiers. Divi membership sites are high-value targets—patch Divi Membership, audit logs, and treat cookie issuance as a signal worth alerting on.