{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3adivi_membershipdivi_membershipwordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:divi_membership:divi_membership:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-19652"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Divi Membership (\u003c= 2.2.0)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Divi Membership plugin for WordPress (versions 2.2.0 and below) is susceptible to an unauthenticated privilege escalation vulnerability. The root cause lies within the \u003ccode\u003edmem_form_submit_handler()\u003c/code\u003e function, which incorrectly assigns user roles by iterating through available WordPress roles and performing a \u003ccode\u003epassword_verify()\u003c/code\u003e check against an attacker-supplied bcrypt hash provided in the \u003ccode\u003eform_id\u003c/code\u003e POST parameter.\u003c/p\u003e\n\u003cp\u003eAn unauthenticated attacker can exploit this by calculating the bcrypt hash of the string \u0026quot;administrator\u0026quot; and submitting it as the \u003ccode\u003eform_id\u003c/code\u003e parameter. Because the function lacks a whitelist of valid roles or validation of the input, the plugin assigns the elevated role to the newly registered account. Furthermore, when the \u003ccode\u003eauto_login=on\u003c/code\u003e parameter is included in the request, the attacker is automatically logged in as the new administrator, facilitating complete site takeover. The required security nonce is publicly exposed on pages hosting the registration form, allowing any unauthenticated visitor to obtain it and initiate the attack.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker navigates to a public-facing page containing the Divi Membership registration form.\u003c/li\u003e\n\u003cli\u003eAttacker inspects the HTML source code to extract the publicly available WordPress nonce required for form submission.\u003c/li\u003e\n\u003cli\u003eAttacker computes the bcrypt hash of the desired role, in this case, \u0026quot;administrator\u0026quot;.\u003c/li\u003e\n\u003cli\u003eAttacker constructs a POST request to the registration handler containing the stolen nonce.\u003c/li\u003e\n\u003cli\u003eAttacker includes the \u003ccode\u003eform_id\u003c/code\u003e POST parameter populated with the computed bcrypt hash and sets the \u003ccode\u003eauto_login\u003c/code\u003e parameter to \u003ccode\u003eon\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003edmem_form_submit_handler()\u003c/code\u003e function processes the input, validates the hash, and assigns the administrator role to the user account being created.\u003c/li\u003e\n\u003cli\u003eThe application returns a successful registration response, and the \u003ccode\u003eauto_login\u003c/code\u003e logic grants the attacker an active session with administrator privileges.\u003c/li\u003e\n\u003cli\u003eAttacker gains full control of the WordPress instance for further exploitation or exfiltration.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in total site compromise. An attacker can gain administrator access to the WordPress environment, allowing them to install malicious plugins, modify site content, exfiltrate user data, or use the server as a base for further lateral movement within the network. All instances of the Divi Membership plugin at version 2.2.0 or earlier are vulnerable.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the Divi Membership plugin to the latest patched version immediately.\u003c/li\u003e\n\u003cli\u003eAudit user accounts for unauthorized administrators created within the last 30 days.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious POST requests targeting the plugin's registration handler.\u003c/li\u003e\n\u003cli\u003eImplement WAF rules to detect and block requests where the \u003ccode\u003eform_id\u003c/code\u003e parameter contains values inconsistent with expected numeric or alphanumeric formatting.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-02T14:24:30Z","date_published":"2026-10-02T14:24:30Z","id":"https://feed.craftedsignal.io/briefs/2026-10-divi-membership-privesc/","summary":"The Divi Membership plugin for WordPress contains an unauthenticated privilege escalation vulnerability (CVE-2026-19652) allowing attackers to register as administrators through improper input validation.","title":"Unauthenticated Privilege Escalation in Divi Membership Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-divi-membership-privesc/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:divi_membership:divi_membership:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}