POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
WordPresscritical

CVE-2026-19660 — Divi Membership (DiviEngine) ≤2.3.0 paypal_param Authentication Bypass

October 2, 2026 · 89 views

DiviEngine Divi Membership ≤2.3.0: process_paypal_callback on init trusts base64 paypal_param GET without PayPal/IPN validation → wp_set_current_user + wp_set_auth_cookie as arbitrary user ID (incl. admin). PayPal gateway class loads even when disabled. CVSS 9.8 Critical (CWE-287). Python PoC: check/exploit, cookie export, mass scan.

#wordpress#divi#divi-membership#diviengine#authentication-bypass#paypal#cwe-287#unauthenticated#critical

CVE:

CVE-2026-19660

Date:

2026-10-02

Severity:

CRITICAL

Exploit source

Full PoC repository on GitHub (public).

Description

Overview

CVE-2026-19660 — Divi Membership WordPress plugin (DiviEngine) — unauthenticated authentication bypass → login as any existing user, including administrators (CWE-287, CVSS 3.1 9.8 Critical).

| | | |---|---| | Product | Divi Membership (DiviEngine) | | Affected | ≤ 2.3.0 | | Fixed | > 2.3.0 (upgrade via Divi Engine — confirm latest release on your license) | | Vector | init hook → process_paypal_callback |

The handler accepts a base64-encoded paypal_param GET parameter with no PayPal IPN validation, no signature check, and no ownership/nonce checks. Attacker-controlled payload supplies a user ID passed to wp_set_current_user() and wp_set_auth_cookie(). The PayPal gateway may be instantiated even when PayPal is not configured, so the vulnerable path can be reachable on front-end requests.

PoC page: https://pocbit.org/pocs/cve-2026-19660

GitHub: murrez/CVE-2026-19660

CVE.org: CVE-2026-19660

NVD: CVE-2026-19660

Attack chain (summary)

  1. Craft paypal_param (base64) encoding attacker-chosen WordPress user ID (often 1 for admin).
  2. GET any front-end URL with ?paypal_param=... (exact encoding per PoC).
  3. Session cookies issued → verify /wp-admin/ or export cookies (PoC admin / exploit mode).

Check mode fingerprints Divi Membership (readme / markers) without mutating sessions where possible.

Bundled tool (Python 3.9+)

Download poc.py from this page (mirrored from GitHub).

pip install requests

python poc.py check https://target.example/
python poc.py admin https://target.example/ --user-id 1
python poc.py targets.txt
python poc.py targets.txt admin

Discovery hints (your assets only)

Commercial Divi ecosystem plugin—look for Divi Membership / DiviEngine assets, membership checkout pages, and exposed plugin paths under /wp-content/plugins/.

Remediation

  1. Upgrade Divi Membership beyond 2.3.0 per vendor changelog.
  2. Audit admin sessions and access logs for suspicious paypal_param query strings.
  3. Restrict /wp-admin/ by IP where feasible until patched.

See WordPress plugin vulnerabilities guide.

Legal and ethical use

Authorized security testing only.

References

Related PoCs

Same platform, vendor, or tags — explore more write-ups on Pocbit.

Browse full PoC archive →