CVE WATCH / VULNERABILITY DETAIL

CVE-2026-19652

CRITICALCVSS 9.8NVD feed

Published 2 October 2026 · tracked since 3 October 2026

Description

The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and calling `password_verify()` against an attacker-contro

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-19652 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-19652

CRITICALCVSS 9.8NVD feed

Published 2 October 2026 · tracked since 3 October 2026

Description

The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and calling `password_verify()` against an attacker-contro

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]