HIGH
clavaque
CVE published 2026-09-25
CVE-2026-19804
The s2Member plugin for WordPress is vulnerable to Remote Code Execution due to insufficient sanitization of user input in the 'first_name' parameter. This allows unauthenticated attackers to execute code on the server if the site administrator has configured a Signup Tracking Codes template with the %%first_name%% placeholder and the attacker has obtained the site-global proxy verification key.