CVE WATCH / VULNERABILITY DETAIL

CVE-2026-19660

CRITICALCVSS 9.8NVD feed

Published 2 October 2026 · tracked since 2 October 2026

Description

The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature c

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-19660 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-19660

CRITICALCVSS 9.8NVD feed

Published 2 October 2026 · tracked since 2 October 2026

Description

The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature c

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]