Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-19652— Divi Membership <= 2.2.0 - Unauthenticated Privilege Escalation via 'form_id' Parameter

Quick assessment

Affected
DiviEngine Divi Membership
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 的 Divi Membership 插件在 2.2.0 及以下版本中存在权限提升漏洞。该漏洞是由于 函数在确定新用户角色时,遍历所有 WordPress 角色,并使用 函数与攻击者控制的 bcrypt 哈希值进行比对——该哈希值通过 POST 参数 提供,且未对允许的角色进行任何验证或白名单限制。因此,未认证的攻击者可以通过提交一个本地计算得到的、代表 (管理员)角色的 bcrypt 哈希值作为 参数,从而注册具有管理员权限的新账户;当同时提交 时,攻击者将在同一请求中立即以该管理员身份被认证登

CVSS 9.8 · Critical

Affected Version Matrix 1

VendorProduct Version RangeStatus
DiviEngine Divi Membership ≤ 2.2.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-19652

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Divi Membership <= 2.2.0 - Unauthenticated Privilege Escalation via 'form_id' Parameter
Source: CVE Program / CVE List V5
Vulnerability Description
The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and calling `password_verify()` against an attacker-controlled bcrypt hash supplied in the `form_id` POST parameter, with no validation or whitelist of allowed roles. This makes it possible for unauthenticated attackers to register a new account with the administrator role by submitting a locally computed bcrypt hash of `administrator` as `form_id`, and when `auto_login=on` is submitted, be immediately authenticated as that administrator in the same request, resulting in full site takeover. Exploitation requires a WordPress nonce, but that nonce is publicly emitted on any page rendering the Divi Membership registration form and is therefore obtainable by any unauthenticated visitor.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
特权管理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
DiviEngine Divi Membership 0 ~ 2.2.0 -

II. Public POCs for CVE-2026-19652

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-19652

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-19652 (1)

Other References for CVE-2026-19652 (1)

Other References for CVE-2026-19652 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-19652

No comments yet


Leave a comment