CVE-2026-19804 | clavaque s2Member Plugin prior 260814 on WordPress esc_refs first_name os command injection (ID 260814)

SecurityVulns

A vulnerability marked as critical has been reported in clavaque s2Member Plugin on WordPress. Affected by this issue is the function esc_refs. This manipulation of the argument first_name causes os command injection.

This vulnerability is handled as CVE-2026-19804. The attack can be initiated remotely. There is not any exploit available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More