Divi Membership Auth Bypass via PayPal Callback Hook
Divi Membership through 2.3.0 has an authentication bypass in its PayPal callback function hooked to the init action without adequate caller verification.
- Vendor
- Divi Engine
- Product
- Divi Membership WordPress Plugin (versions up to and including 2.3.0)
- CVSS
- 9.8
- EPSS (exploit probability)
- 0.4%
- Status
- patched
- Published
CVE-2026-19660 is a CVSS 9.8 critical authentication bypass in the Divi Membership WordPress plugin, affecting all versions up to and including 2.3.0. The process_paypal_callback function is hooked to the WordPress init action and lacks adequate verification that the caller is a legitimate PayPal webhook. An unauthenticated attacker can trigger it directly, bypassing the authentication checks that should gate access to membership functionality.
Site administrators running Divi Membership should update through the WordPress admin dashboard. Deactivating the plugin until a patch can be applied removes the attack surface.
Source: NVD.