CVE-2026-19660 — Divi Membership (DiviEngine) ≤2.3.0 paypal_param Authentication Bypass
October 2, 2026 · 89 views
DiviEngine Divi Membership ≤2.3.0: process_paypal_callback on init trusts base64 paypal_param GET without PayPal/IPN validation → wp_set_current_user + wp_set_auth_cookie as arbitrary user ID (incl. admin). PayPal gateway class loads even when disabled. CVSS 9.8 Critical (CWE-287). Python PoC: check/exploit, cookie export, mass scan.
Description
Overview
CVE-2026-19660 — Divi Membership WordPress plugin (DiviEngine) — unauthenticated authentication bypass → login as any existing user, including administrators (CWE-287, CVSS 3.1 9.8 Critical).
| | |
|---|---|
| Product | Divi Membership (DiviEngine) |
| Affected | ≤ 2.3.0 |
| Fixed | > 2.3.0 (upgrade via Divi Engine — confirm latest release on your license) |
| Vector | init hook → process_paypal_callback |
The handler accepts a base64-encoded paypal_param GET parameter with no PayPal IPN validation, no signature check, and no ownership/nonce checks. Attacker-controlled payload supplies a user ID passed to wp_set_current_user() and wp_set_auth_cookie(). The PayPal gateway may be instantiated even when PayPal is not configured, so the vulnerable path can be reachable on front-end requests.
PoC page: https://pocbit.org/pocs/cve-2026-19660
GitHub: murrez/CVE-2026-19660
CVE.org: CVE-2026-19660
NVD: CVE-2026-19660
Attack chain (summary)
- Craft
paypal_param(base64) encoding attacker-chosen WordPress user ID (often1for admin). - GET any front-end URL with
?paypal_param=...(exact encoding per PoC). - Session cookies issued → verify
/wp-admin/or export cookies (PoC admin / exploit mode).
Check mode fingerprints Divi Membership (readme / markers) without mutating sessions where possible.
Bundled tool (Python 3.9+)
Download poc.py from this page (mirrored from GitHub).
pip install requests
python poc.py check https://target.example/
python poc.py admin https://target.example/ --user-id 1
python poc.py targets.txt
python poc.py targets.txt admin
Discovery hints (your assets only)
Commercial Divi ecosystem plugin—look for Divi Membership / DiviEngine assets, membership checkout pages, and exposed plugin paths under /wp-content/plugins/.
Remediation
- Upgrade Divi Membership beyond 2.3.0 per vendor changelog.
- Audit admin sessions and access logs for suspicious
paypal_paramquery strings. - Restrict
/wp-admin/by IP where feasible until patched.
See WordPress plugin vulnerabilities guide.
Legal and ethical use
Authorized security testing only.
References
Related PoCs
Same platform, vendor, or tags — explore more write-ups on Pocbit.
- WordPressCVE-2026-14378critical
CVE-2026-14378 — DevKit Pro ≤2.3.0 Unauthenticated Admin Takeover (User-Switch Revert)
WordPress DevKit Pro (dplugins) ≤2.3.0: forged original_user_id cookie + wp_footer revert_switch nonce; verify_nonce_and_capability checks manage_options for forged user, not current requester → wp_set_auth_cookie admin session. CVSS 9.8 Critical (CWE-287). Fixed 3.0.0+. Python PoC: check (footer oracle), admin exploit, mass scan 50 threads.
- WordPressCVE-2026-87902critical
CVE-2026-87902 — WordPress Core get_page_template() Unauthenticated LFI → RCE (PEAR chain)
WordPress core 4.7.0–7.1.1: pagename from POST used in get_page_template() without validate_file(); page-templates/ traversal + PEAR gadget → RCE. GHSA-7hp8-65ch-5whp, CVSS 4.0 9.8, CWE-22. Fixed 7.1.2+ (backports 6.8.10, 7.0.6). Python mass scanner: --check, --rce, --shell. Upstream: MRdark-ops/CVE-2026-87902 (HackfutSecRoot).
- WordPressCVE-2026-96349critical
CVE-2026-96349 — WordPress SiteSkite ≤2.1.8 API-Key Autologin + MCP eval() RCE Chain
SiteSkite WordPress plugin ≤2.1.8: long-lived API key acts as unauthenticated admin bearer via ?token= autologin; REST/admin-ajax MCP abilities run siteskite_execute_php (eval) and file write. CVSS 10.0 Critical (CWE-94). Fixed in 2.2.0. Python PoC: check (readme ≤2.1.8), exploit with API key, mass hits/exploited, --lab. Marker POCBIT-96349-OK.
- WordPressCVE-2026-92966critical
CVE-2026-92966 — WordPress LatePoint ≤5.7.0 Stored Shortcode Execution (Customer Cabinet)
LatePoint appointment booking ≤5.7.0: unauthenticated guest booking stores [shortcode] in customer first/last name (sanitize_text_field keeps brackets); Customer Cabinet block renders welcome line then the_content do_shortcode runs twice → arbitrary shortcode execution. CVSS 9.1 Critical (CWE-94). Fixed in 5.7.1. No API key. Python PoC: check, mass exploit, --lab, optional POCBIT_EXEC_SHORTCODE. Marker POCBIT-92966-OK.