PT-2026-98385 · WordPress · S2Member
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
s2Member versions prior to 260829
Description
Unauthenticated attackers can achieve Remote Code Execution on the server due to insufficient sanitization of the
first name parameter. The plugin uses the esc refs() function, which only removes regex backreferences and fails to strip PHP tags before the parameter is substituted into the evaluated Signup Tracking Codes template. This issue is further enabled by the exposure of the site-global proxy verification key in plaintext within the JSON response of any PayPal Checkout AJAX request, allowing the PayPal postback verification to be bypassed. Successful exploitation requires the site administrator to have configured a Signup Tracking Codes template that includes the %%first name%% placeholder.Recommendations
Update to version 260829 or newer.
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
S2Member