PT-2026-98385 · WordPress · S2Member

·

CVE-2026-19804

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions s2Member versions prior to 260829
Description Unauthenticated attackers can achieve Remote Code Execution on the server due to insufficient sanitization of the first name parameter. The plugin uses the esc refs() function, which only removes regex backreferences and fails to strip PHP tags before the parameter is substituted into the evaluated Signup Tracking Codes template. This issue is further enabled by the exposure of the site-global proxy verification key in plaintext within the JSON response of any PayPal Checkout AJAX request, allowing the PayPal postback verification to be bypassed. Successful exploitation requires the site administrator to have configured a Signup Tracking Codes template that includes the %%first name%% placeholder.
Recommendations Update to version 260829 or newer.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19804

Affected Products

S2Member