CVE-2026-19652
Description
The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the dmem_form_submit_handler() function determining the new user's role by iterating all WordPress roles and calling password_verify() against an attacker-controlled bcrypt hash supplied in the form_id POST parameter, with no validation or whitelist of allowed roles. This makes it possible for unauthenticated attackers to register a new account with the administrator role by submitting a locally computed bcrypt hash of administrator as form_id, and when auto_login=on is submitted, be immediately authenticated as that administrator in the same request, resulting in full site takeover. Exploitation requires a WordPress nonce, but that nonce is publicly emitted on any page rendering the Divi Membership registration form and is therefore obtainable by any unauthenticated visitor.
Affected products
1- Range: <=2.2.0
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.