<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Divi Membership (&lt;= 2.2.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/divi-membership--2.2.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 14:24:30 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/divi-membership--2.2.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Privilege Escalation in Divi Membership Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-divi-membership-privesc/</link><pubDate>Fri, 02 Oct 2026 14:24:30 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-divi-membership-privesc/</guid><description>The Divi Membership plugin for WordPress contains an unauthenticated privilege escalation vulnerability (CVE-2026-19652) allowing attackers to register as administrators through improper input validation.</description><content:encoded><![CDATA[<p>The Divi Membership plugin for WordPress (versions 2.2.0 and below) is susceptible to an unauthenticated privilege escalation vulnerability. The root cause lies within the <code>dmem_form_submit_handler()</code> function, which incorrectly assigns user roles by iterating through available WordPress roles and performing a <code>password_verify()</code> check against an attacker-supplied bcrypt hash provided in the <code>form_id</code> POST parameter.</p>
<p>An unauthenticated attacker can exploit this by calculating the bcrypt hash of the string &quot;administrator&quot; and submitting it as the <code>form_id</code> parameter. Because the function lacks a whitelist of valid roles or validation of the input, the plugin assigns the elevated role to the newly registered account. Furthermore, when the <code>auto_login=on</code> parameter is included in the request, the attacker is automatically logged in as the new administrator, facilitating complete site takeover. The required security nonce is publicly exposed on pages hosting the registration form, allowing any unauthenticated visitor to obtain it and initiate the attack.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker navigates to a public-facing page containing the Divi Membership registration form.</li>
<li>Attacker inspects the HTML source code to extract the publicly available WordPress nonce required for form submission.</li>
<li>Attacker computes the bcrypt hash of the desired role, in this case, &quot;administrator&quot;.</li>
<li>Attacker constructs a POST request to the registration handler containing the stolen nonce.</li>
<li>Attacker includes the <code>form_id</code> POST parameter populated with the computed bcrypt hash and sets the <code>auto_login</code> parameter to <code>on</code>.</li>
<li>The <code>dmem_form_submit_handler()</code> function processes the input, validates the hash, and assigns the administrator role to the user account being created.</li>
<li>The application returns a successful registration response, and the <code>auto_login</code> logic grants the attacker an active session with administrator privileges.</li>
<li>Attacker gains full control of the WordPress instance for further exploitation or exfiltration.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in total site compromise. An attacker can gain administrator access to the WordPress environment, allowing them to install malicious plugins, modify site content, exfiltrate user data, or use the server as a base for further lateral movement within the network. All instances of the Divi Membership plugin at version 2.2.0 or earlier are vulnerable.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade the Divi Membership plugin to the latest patched version immediately.</li>
<li>Audit user accounts for unauthorized administrators created within the last 30 days.</li>
<li>Monitor web server logs for suspicious POST requests targeting the plugin's registration handler.</li>
<li>Implement WAF rules to detect and block requests where the <code>form_id</code> parameter contains values inconsistent with expected numeric or alphanumeric formatting.</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>