CVE-2026-19652 PUBLISHED

Divi Membership <= 2.2.0 - Unauthenticated Privilege Escalation via 'form_id' Parameter

Assigner: Wordfence
Reserved: 12.08.2026 Published: 02.10.2026 Updated: 02.10.2026

The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the dmem_form_submit_handler() function determining the new user's role by iterating all WordPress roles and calling password_verify() against an attacker-controlled bcrypt hash supplied in the form_id POST parameter, with no validation or whitelist of allowed roles. This makes it possible for unauthenticated attackers to register a new account with the administrator role by submitting a locally computed bcrypt hash of administrator as form_id, and when auto_login=on is submitted, be immediately authenticated as that administrator in the same request, resulting in full site takeover. Exploitation requires a WordPress nonce, but that nonce is publicly emitted on any page rendering the Divi Membership registration form and is therefore obtainable by any unauthenticated visitor.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor DiviEngine
Product Divi Membership
Versions Default: unaffected
  • affected from 0 to 2.2.0 (incl.)

Credits

  • 0xd4rk5id3 finder

References

Problem Types

  • CWE-269 Improper Privilege Management CWE