VYPR

Divi Membership

by WordPress

CVEs (1)

  • CVE-2026-19660CriOct 2, 2026
    risk 0.64cvss 9.8epss —

    The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no…