Mike McGugan[verified]@cirruxActive Exploitation
The user reports widespread traffic containing the CVE-2026-1994-POC user agent across multiple sites, indicating ongoing exploitation in the wild.
Quttera - eCommerce Security[verified]@MNovofastovskyPatch
The post discloses a critical privilege‑escalation flaw in the s2Member WordPress plugin and recommends immediate patching and monitoring for malicious activity.
CVETodo[verified]@CveTodoDisclosure
The post announces a critical privilege‑escalation flaw in the s2Member WordPress plugin, detailing how unauthenticated attackers can change passwords and potentially take over sites.
OffSeq | Adversary Tactics for Cyber Resilience[verified]@offseqDisclosure
The tweet announces CVE‑2026‑1994, a critical flaw in s2Member that lets attackers reset WordPress passwords and potentially seize the site, urging users to disable the plugin and await vendor patches.
Dark Web Informer@DarkWebInformerExploit
The post announces the sale of a compiled GoLang exploit targeting CVE‑2026‑1994, a high‑severity WordPress privilege‑escalation flaw, with no patch information or evidence of current in‑the‑wild exploitation.
The Hacker Wire@TheHackerWireDisclosure
A privilege‑escalation flaw has been disclosed in the s2Member WordPress plugin (all versions up to 260127), allowing attackers to take over user accounts by exploiting improper validation.
CVE@CVEnewDisclosure
The s2Member plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to 260127.
0day Signal@0dayPublishingDisclosure
CVE-2026-1994 is a zero‑day vulnerability in s2Member that allows unauthenticated hijacking of admin accounts by skipping identity validation during password changes. A link to the vulnerability page is provided, but no exploit code, patch, or active exploitation claim is mentioned.