CRITICAL
9.8 CVE-2026-19652 Published 2 Oct 2026
Divi Membership WordPress Plugin Privilege Escalation Vulnerability
Worried this affects your website?
The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0.
The flaw exists in the dmem_form_submit_handler() function, which determines a new user's role by iterating all WordPress roles and calling password_verify() against an attacker-controlled bcrypt hash supplied in the form_id POST parameter, with no validation or whitelist of allowed roles.
- Affected versions: up to and including 2.2.0
- Attack type: unauthenticated privilege escalation to administrator
- Impact: full site takeover
- Precondition: a WordPress nonce, publicly emitted on any page rendering the Divi Membership registration form
By submitting a locally computed bcrypt hash of administrator as form_id, and with auto_login=on, an unauthenticated attacker can register an administrator account and be immediately authenticated in the same request.
Reference: CVE-2026-19652 on NVD
← Back to Security News