OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-19652

CRITICAL · CVSS 9.8 EPSS 0.33% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The Divi Membership plugin for WordPress is vulnerable to privilege escalation, allowing unauthenticated attackers to register as an administrator by exploiting the `dmem_form_submit_handler()` function. By submitting a crafted bcrypt hash in the `form_id` POST parameter, attackers can gain immediate access to the site with full administrative privileges. WordPress site administrators using versions up to 2.2.0 of this plugin should prioritize patching this critical vulnerability to prevent potential site takeovers.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19652
Severity
CRITICAL
CVSS
9.8
EPSS
0.33%
WordPress

Original NVD Description

The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and calling `password_verify()` against an attacker-controlled bcrypt hash supplied in the `form_id` POST parameter, with no validation or whitelist of allowed roles. This makes it possible for unauthenticated attackers to register a new account with the administrator role by submitting a locally computed bcrypt hash of `administrator` as `form_id`, and when `auto_login=on` is submitted, be immediately authenticated as that administrator in the same request, resulting in full site takeover. Exploitation requires a WordPress nonce, but that nonce is publicly emitted on any page rendering the Divi Membership registration form and is therefore obtainable by any unauthenticated visitor.