POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
← Blog

Divi Membership paypal_param Bypass (CVE-2026-19660): Fake PayPal, Real Admin Cookies

Admin · October 2, 2026 · 7 views

Divi Membership and the fake PayPal callback

Divi Membership by DiviEngine powers paid membership sites on Divi: plans, Stripe/PayPal, trials, and gated content. CVE-2026-19660 (CWE-287 Improper Authentication, CVSS 3.1 9.8 Critical) affects ≤ 2.3.0: an init hook handler process_paypal_callback trusts a base64 paypal_param GET value without PayPal IPN validation, signature verification, or membership ownership checks—then calls wp_set_current_user() and wp_set_auth_cookie() for an attacker-chosen user ID.

Catalog and tooling: CVE-2026-19660 on pocbit.org. Repository: murrez/CVE-2026-19660.

Why this hits even “PayPal disabled” shops

Reports emphasize that the PayPal gateway class may be constructed on every front-end request, even when PayPal is not configured or enabled. That means the vulnerable init path can exist without merchants consciously turning on PayPal—membership sites using Stripe-only billing may still be exposed until patched.

Impact: login as any existing WordPress user, including administrators, via a crafted query string—full site takeover without wp-login noise.

Defender checklist

| # | Action | Detail | |---|--------|--------| | 1 | Inventory Divi Membership version | License portal / plugin header; compare to > 2.3.0 | | 2 | Upgrade immediately | Divi Membership changelog | | 3 | Search logs for paypal_param= on anonymous GETs | Especially before new wordpress_logged_in_* cookies | | 4 | Invalidate admin sessions after upgrade | Assume compromise if suspicious params appeared | | 5 | Restrict /wp-admin/ by IP during maintenance | Bridge control only |

Pair with how to prioritize critical CVEs and WordPress security checklist (2026).

Not the same as other “PayPal webhook” CVEs

WordPress ecosystem sees multiple PayPal-adjacent bugs (webhook signature bypass on other membership plugins, etc.). CVE-2026-19660 is specific to DiviEngine’s paypal_param callback on init—WAF and detection rules must match this parameter name and encoding, not generic PayPal paths.

Detection hints (your assets only)

Membership stacks on Divi often expose registration/checkout pages and DiviEngine branding. Hunt your own estates for Divi Membership plugin paths and version markers—use results for ticketing, not third-party probing.

Patch validation in a lab

  1. Licensed lab install with Divi Membership ≤ 2.3.0.
  2. Run public PoC check mode, then authorized exploit against the lab host.
  3. Upgrade beyond 2.3.0; confirm callback no longer mints sessions for forged params.

See safe PoC lab setup.

FAQ

We only use Stripe—skip the patch?

No. Upgrade based on vendor fixed version; do not assume payment UI reflects which hooks are registered.

Is base64 in query strings enough to WAF-block?

Temporary rule on paypal_param helps during rollout; vendor fix removes the trust boundary failure.

Bottom line

CVE-2026-19660 shows that any code path that sets auth cookies must validate payment reality, not attacker-supplied identifiers. Divi membership sites are high-value targets—patch Divi Membership, audit logs, and treat cookie issuance as a signal worth alerting on.