CVE-2026-19652 is a Privilege Escalation vulnerability in the Divi Membership plugin for WordPress, allowing unauthenticated attackers to register as administrators. The vulnerability exists due to improper validation of user roles in the `dmem_form_submit_handler()` function. Exploitation requires a publicly obtainable WordPress nonce. This vulnerability can lead to full site takeover and elevation of pr [truncated]
The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. This makes it possible for unauthenticated attackers to log in as any existing WordPress user — including administrators — by supplying an arbitrary user ID in the `paypal_param` GET parameter, resulting in full site takeover.