🚨 CVE-2026-19660

CVENOTIFYneutralcrypto2026-10-02 05:20:52 UTC
AdYour ad here[email protected]

🚨 CVE-2026-19660 The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature check, no ownership verification, and no nonce, allowing it to trust an entirely attacker-controlled user ID value that is passed directly to `wp_set_current_user()` and…

Read the full story at cvenotify ↗
AdYour ad here[email protected]