Divi Membership for WordPress through version 2.3.0 contains an authentication bypass in process_paypal_callback, which is hooked to the WordPress init action. The function accepts a base64-encoded paypal_param GET parameter without validating PayPal IPN data, a cryptographic signature, user ownership, or a nonce. It passes the attacker-controlled user ID directly to wp_set_current_user() and wp_set_auth_cookie(), allowing an unauthenticated attacker to establish a session as any existing user, including an administrator. The PayPal gateway class is instantiated unconditionally, exposing the callback on every front-end request even when PayPal is disabled or unconfigured.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This four-file Python repository contains an operational proof-of-concept for CVE-2026-14378, an unauthenticated administrator-session takeover in dplugins DevKit Pro versions up to 2.3.0. The principal code file, poc.py, uses requests with TLS certificate verification disabled, randomized browser-like headers, redirects enabled, and HTTP/HTTPS fallback. It fingerprints likely plugin installations through several exposed readme or PHP paths, then sets the attacker-controlled original_user_id cookie and requests public WordPress pages to detect a leaked user-switch revert nonce in wp_footer. In admin mode it submits the extracted nonce to /wp-admin/admin-ajax.php using revert_switch and three plausible plugin-specific action aliases, seeking a wordpress_logged_in_* cookie and validating access through /wp-admin/. The script supports detection-only checks, selected user IDs, sequential user-ID brute forcing, result logging, and threaded mass scanning of URL lists (default 50 workers). README.md documents the vulnerability, usage, mitigations, and expected behavior; requirements.txt declares requests>=2.28.0; LICENSE is MIT. This is standalone code rather than a recognized exploit framework module.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.