CVE-2026-1994Disclosure

HIGHCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The s2Member plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 260127. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 3 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 6 mentions (2026-02-19); latest day: 1
  • 8 total mentions across 3 days

Deep dive

Activity timeline8 mentions / 3d
02356Mentions · 2026-02-19: 6Mentions · 2026-03-05: 1Mentions · 2026-04-04: 1PoC Mentioned / Linked · 2026-02-19: 2PoC Mentioned / Linked · 2026-04-04: 1Exploit Tool / Code · 2026-02-19: 1Active Exploitation · 2026-04-04: 1Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-03-05: 1Technical Details · 2026-02-19: 6Technical Details · 2026-03-05: 102-1903-0504-04
Signal classification4 categories
Disclosure
562.5%
Exploit
112.5%
Patch
112.5%
Active Exploitation
112.5%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-196
Disclosure5Exploit1
2026-03-051
Patch1
2026-04-041
Active Exploitation1
Full discourse8 posts
  • Dark Web Informer@DarkWebInformer
    Exploit

    ‼️ A threat actor is selling a compiled exploit for CVE-2026-1994 (CVSS 9.8), an unauthenticated privilege escalation via account takeover vulnerability in the WordPress s2Member plugin. The exploit is written in GoLang with builds available for Windows and macOS. Code is priced at $200, builds at $100, with exclusive sale options available.

    Post summary

    The post announces the sale of a compiled GoLang exploit targeting CVE‑2026‑1994, a high‑severity WordPress privilege‑escalation flaw, with no patch information or evidence of current in‑the‑wild exploitation.

    22037164.6K
    162.4K followersView on X
  • Mike McGugan@cirrux
    Active Exploitation

    @andrewhoyer Yes, been getting these all day on many different sites, but only once per user. The user agent for all of the requests contains "CVE-2026-1994-POC", so it's intentional I guess

    Post summary

    The user reports widespread traffic containing the CVE-2026-1994-POC user agent across multiple sites, indicating ongoing exploitation in the wild.

    10010309
    24 followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    CVE-2026-1994 Critical WordPress Vulnerability (CVSS 9.8) The s2Member plugin (≤ 260127) contains a privilege escalation flaw that allows unauthenticated attackers to reset arbitrary user passwords—including administrator accounts. Once exploited, attackers can take over the site, inject malware, or deploy SEO spam and payment skimmers. 🔧 How to mitigate: • Update the s2Member plugin immediately • Audit WordPress admin accounts & password changes • Scan for injected malware or unauthorized files 🔎 Detect hidden infections and malicious scripts: https://quttera.com/wordpress-malware-scanner #WordPress #CVE #CyberSecurity #WebsiteSecurity #SilentRisk

    Post summary

    The post discloses a critical privilege‑escalation flaw in the s2Member WordPress plugin and recommends immediate patching and monitoring for malicious activity.

    0000042
    37 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-1994 - Critical The s2Member plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 260127. This is due to the plugin not properly validating... https://www.thehackerwire.com/vulnerability/CVE-2026-1994/ https://t.co/iwEv1kKrSA

    Post summary

    A privilege‑escalation flaw has been disclosed in the s2Member WordPress plugin (all versions up to 260127), allowing attackers to take over user accounts by exploiting improper validation.

    0000047
    112 followersView on X
  • CVETodo@CveTodo
    Disclosure

    CVE-2026-1994 pertains to a critical privilege escalation vulnerability in the s2Member plugin for WordPress. The core issue is that the plugin fails to properly validate a user's identity before allowing password updates. This flaw enables unauthenticated attackers to change the passwords of arbitrary user accounts, including highly privileged accounts such as administrators. By doing so, attackers can fully compromise affected accounts, leading to potential full site takeover. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution #PrivilegeEscalation https://cvetodo.com/cve/CVE-2026-1994

    Post summary

    The post announces a critical privilege‑escalation flaw in the s2Member WordPress plugin, detailing how unauthenticated attackers can change passwords and potentially take over sites.

    0000028
    20 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1994 The s2Member plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 260127. This is due to the plugin not… https://www.cve.org/CVERecord?id=CVE-2026-1994

    Post summary

    The s2Member plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to 260127.

    00000116
    56.4K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Disclosure

    🚨 CRITICAL: CVE-2026-1994 in s2Member lets unauthenticated attackers reset any WordPress user's password — risk of full site takeover! Disable plugin & monitor for patches. https://radar.offseq.com/threat/cve-2026-1994-cwe-269-improper-privilege-managemen-8fe39267 #OffSeq #Wor... https://t.co/jJPmStiK0Y

    Post summary

    The tweet announces CVE‑2026‑1994, a critical flaw in s2Member that lets attackers reset WordPress passwords and potentially seize the site, urging users to disable the plugin and await vendor patches.

    0000029
    265 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-1994: s2Member <= 260127 - Unauthentica... Zero-day in s2Member skips identity validation during password changes, enabling unauthenticated admin account hijacking... https://zerodaysignal.com/vulnerability/CVE-2026-1994 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-1994 is a zero‑day vulnerability in s2Member that allows unauthenticated hijacking of admin accounts by skipping identity validation during password changes. A link to the vulnerability page is provided, but no exploit code, patch, or active exploitation claim is mentioned.

    0000051
    131 followersView on X

Explore more