Security Alert Summary
The Divi Membership plugin for WordPress contains a privilege escalation vulnerability that can allow an unauthenticated attacker to create a new account with the administrator role and be automatically authenticated in the same request. The issue stems from insufficient validation of a POST parameter used when registering users.
CVE Details
- CVE ID: CVE-2026-19652
- Affected component: Divi Membership plugin for WordPress
- Affected versions: versions up to, and including, 2.2.0
- Published: October 2, 2026 2:17:10 PM UTC
- Last modified: October 2, 2026 2:17:10 PM UTC
- CVSS v3.1: Base Score 9.8, Severity CRITICAL
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Authentication / privileges / interaction:
- Authentication required: No
- Privileges required: None
- User interaction: None
- Primary impact: Confidentiality: High; Integrity: High; Availability: High
- Weakness (CWE): CWE-269
Technical Details
The vulnerability exists in the plugin function dmem_form_submit_handler(). When handling registration, this function determines the new user\’s role by iterating over all WordPress roles and calling password_verify() against a bcrypt hash supplied by the requester in the form_id POST parameter. The implementation lacks validation or a whitelist of allowed roles for registration.
An attacker can locally compute a bcrypt hash of the literal string administrator, supply that hash as form_id, and the plugin will accept the matching role when password_verify() returns true. If the additional parameter auto_login=on is submitted, the plugin performs authentication in the same request, allowing the newly created administrator account to be immediately authenticated.
Exploitation requires a WordPress nonce, but the plugin emits that nonce on any page that renders the Divi Membership registration form, making the nonce obtainable by unauthenticated visitors. The combined effect is the ability for an unauthenticated actor to create and immediately assume an administrator account, potentially resulting in full site takeover.
How This Could Impact Your Website
Consider a small business site where the site owner manages content, internal staff members contribute posts, and an external contractor occasionally updates theme or plugin files. If the site uses the affected Divi Membership versions, an unauthenticated attacker could register an administrator account and log in immediately. That attacker could then access dashboards, view or export user email addresses, and modify content or plugins.
Practical consequences include exposure of internal user email addresses, increased risk of targeted phishing or social engineering against staff or contractors, and unauthorized changes to site content or configuration. If an attacker obtains administrator access, they can also install backdoors or persistent access mechanisms, which increases the recovery effort.
professional review If you\’re unsure whether your site is affected or how to assess your current user roles and plugins, it may be worth having a professional review of your setup.
Recommended Actions
- Update the affected plugin as soon as a patched version is available.
- Review and reduce unnecessary user roles, especially contributor-level and higher accounts.
- Enforce strong passwords and enable two-factor authentication for editors and administrators.
- Remove unused or unmaintained plugins and themes from the site.
- Monitor site activity and authentication logs for unusual behavior, new administrator accounts, or unexpected logins.
If you\’d like help reviewing your plugins, user roles, or overall WordPress security posture, our team at Freshy is happy to help.