Product
An unauthenticated remote code execution vulnerability (CVE-2026-19804) exists in the s2Member WordPress plugin, allowing attackers to execute code via the first_name parameter when combined with a leaked proxy verification key.