OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-19804

HIGH · CVSS 8.8 EPSS 1.04% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The s2Member plugin for WordPress is vulnerable to Remote Code Execution due to insufficient sanitization of the 'first_name' parameter, allowing unauthenticated attackers to execute arbitrary code on the server. This vulnerability is exacerbated by the exposure of the site-global proxy verification key in plaintext during PayPal Checkout AJAX requests, enabling attackers to bypass security measures. WordPress site administrators using this plugin should prioritize patching this vulnerability, especially if they have configured the Signup Tracking Codes template with the %%first_name%% placeholder.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19804
Severity
HIGH
CVSS
8.8
EPSS
1.04%
WordPress

Original NVD Description

The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 260814 via the 'first_name' parameter parameter. This is due to insufficient sanitization of the first_name parameter via esc_refs(), which strips only regex backreferences and not PHP tags, before substitution into the eval'd Signup Tracking Codes template, combined with disclosure of the site-global proxy verification key that allows PayPal postback verification to be bypassed. This makes it possible for unauthenticated attackers to execute code on the server. Successful exploitation requires that the site administrator has configured a Signup Tracking Codes template containing the %%first_name%% placeholder (a documented, GUI-supported feature) and that the attacker has obtained the site-global proxy verification key, which is exposed in plaintext in the JSON response of any PayPal Checkout AJAX request on the target site.