Eklenti güvenlik geçmişi
Divi Membership güvenlik açıkları
ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) Divi Membership eklentisi için 2 açık kaydı bulunuyor; en yenisi 2 Ekim 2026 tarihli. Bunların 2 tanesi kritik veya yüksek önemde, 2 tanesi oturum açmadan istismar edilebiliyor.
- Toplam kayıt
- 2
- Kritik veya yüksek
- 2
- Oturumsuz istismar
- 2
- Son kayıt
- 2 Ekim 2026
Bilinen açık kayıtları
En yeniden eskiye. Her kaydın özgün metni NVD’de.
yetki yükseltme
Etkilenen sürümler: 2.2.0 ve öncesi · Oturum açmadan istismar edilebilir
The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and calling `password_verify()` against an attacker-controlled bcrypt hash supplied in the `form_id` POST parameter, with no validation or whitelist of allowed roles. This makes it possible for unauthenticated attackers to register a new account with the administrator role by submitting a locally computed bcrypt hash of `administrator` as `form_id`, and when `auto_login=on` is submitted, be immediately authenticated as that administrator in the same request, resulting in full site takeover. Exploitation requires a WordPress nonce, but that nonce is publicly emitted on any page rendering the Divi Membership registration form and is therefore obtainable by any unauthenticated visitor.
Türkçe kayıt ve ne yapmalıkimlik doğrulama atlatma
Etkilenen sürümler: 2.3.0 ve öncesi · Oturum açmadan istismar edilebilir
The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no cryptographic signature check, no ownership verification, and no nonce, allowing it to trust an entirely attacker-controlled user ID value that is passed directly to `wp_set_current_user()` and `wp_set_auth_cookie()`. This makes it possible for unauthenticated attackers to log in as any existing WordPress user — including administrators — by supplying an arbitrary user ID in the `paypal_param` GET parameter, resulting in full site takeover. The vulnerability is further compounded by the fact that the PayPal gateway class is instantiated unconditionally regardless of whether PayPal is enabled or configured, ensuring the vulnerable hook is always registered on every front-end request.
Türkçe kayıt ve ne yapmalı
Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 7 Ekim 2026 itibarıyla.