CVE-2026-19660 - Divi Membership <= 2.3.0 - Unauthenticated Authentication Bypass via 'paypal_param' Parameter
CVE ID :CVE-2026-19660 Published : Oct. 2, 2026, 4:27 a.m. | 52 minutes ago Description :The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a...