plugin

S2Member Vulnerabilities

24 known security issues reported for the S2Member WordPress plugin. Most recent disclosed Aug 7, 2026.

3 critical 5 high 5 medium

Running S2Member on your site? Check whether your installed version is affected.

Scan your site free

s2Member <= 260804 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The s2Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 260804 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that w...

CVSS:
6.4
Affected:
up to 260804
Fixed in:
260805
Disclosed:
Aug 7, 2026

CVE-2026-15047 on NVD →

s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls &amp; Member Access Subscriptions [s2member] < 260101

unknown

[en] The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 's2Eot' shortcode in all versions up to, and including, 251005 due to insufficient input sanitization and output escap...

Affected:
up to 260101
Fixed in:
260101
Disclosed:
Feb 19, 2026

CVE-2025-13732 on NVD →

s2Member <= 260127 - Unauthenticated Privilege Escalation via Account Takeover

critical

The s2Member plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 260127. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's...

CVSS:
9.8
Affected:
up to 260127
Fixed in:
260215
Disclosed:
Feb 18, 2026

CVE-2026-1994 on NVD →

s2Member <= 251005 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 's2Eot' shortcode in all versions up to, and including, 251005 due to insufficient input sanitization and output escaping....

CVSS:
6.4
Affected:
up to 251005
Fixed in:
260101
Disclosed:
Feb 18, 2026

CVE-2025-13732 on NVD →

s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls &amp; Member Access Subscriptions [s2member] <= 250701 (unfixed)

unknown

[en] Deserialization of Untrusted Data vulnerability in Cristián Lávaque s2Member s2member allows Object Injection.This issue affects s2Member: from n/a through <= 250701.

Affected:
up to 250701
Fix:
No patched version reported
Disclosed:
Nov 6, 2025

CVE-2025-58998 on NVD →

s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls &amp; Member Access Subscriptions [s2member] <= 250905 (unfixed)

unknown

[en] Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member.This issue affects s2Member: from n/a through <= 250905.

Affected:
up to 250905
Fix:
No patched version reported
Disclosed:
Oct 22, 2025

CVE-2025-62023 on NVD →

s2Member <= 250905 - Unauthenticated Remote Code Execution

critical

The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 250905. This makes it possible for unauthenticated attackers to execute code on the server.

CVSS:
9.8
Affected:
up to 250905
Fixed in:
251005
Disclosed:
Oct 1, 2025

CVE-2025-62023 on NVD →

s2Member <= 250701 - Unauthenticated PHP Object Injection

high

The s2Member plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 250701 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an...

CVSS:
8.1
Affected:
up to 250701
Fixed in:
250905
Disclosed:
Aug 21, 2025

CVE-2025-58998 on NVD →

s2Member <= 250419 - Authenticated (Administrator+) Local File Inclusion

high

The s2Member plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 250419 via the 'ws_plugin__s2member_log_file' parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arbitrary files on the server, allowing...

CVSS:
7.2
Affected:
up to 250419
Fixed in:
250424
Disclosed:
Apr 4, 2025

CVE-2025-32137 on NVD →

s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls &amp; Member Access Subscriptions [s2member] < 250424

unknown

[en] Relative Path Traversal vulnerability in Cristián Lávaque s2Member allows Path Traversal. This issue affects s2Member: from n/a through 250214.

Affected:
up to 250424
Fixed in:
250424
Disclosed:
Apr 4, 2025

CVE-2025-32137 on NVD →

s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls &amp; Member Access Subscriptions [s2member] < 250214

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cristián Lávaque s2Member Pro allows Reflected XSS. This issue affects s2Member Pro: from n/a through 241216.

Affected:
up to 250214
Fixed in:
250214
Disclosed:
Mar 3, 2025

CVE-2025-26879 on NVD →

s2Member Pro <= 241216 - Reflected Cross-Site Scripting

medium

The s2Member Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 241216 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully t...

CVSS:
6.1
Affected:
up to 241216
Fixed in:
250214
Disclosed:
Feb 22, 2025

CVE-2025-26879 on NVD →

s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls &amp; Member Access Subscriptions [s2member] < 250214

unknown

[en] The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 241114. This makes it...

Affected:
up to 250214
Fixed in:
250214
Disclosed:
Feb 18, 2025

CVE-2024-11376 on NVD →

s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions <= 241216 - Reflected Cross-Site Scripting

medium

The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 241114. This makes it possi...

CVSS:
6.1
Affected:
up to 241216
Fixed in:
250214
Disclosed:
Feb 17, 2025

CVE-2024-11376 on NVD →

s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions <= 241114 - Authenticated (Contributor+) Sensitive Information Exposure

high

The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 241114 via the 'sc_get_details' function. This makes it possible for authenticated attackers, with...

CVSS:
8.8
Affected:
up to 241114
Fixed in:
241216
Disclosed:
Dec 16, 2024

CVE-2024-8326 on NVD →

s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls &amp; Member Access Subscriptions [s2member] < 241216

unknown

[en] Improper Control of Generation of Code ('Code Injection') vulnerability in WP Sharks s2Member Pro allows Code Injection.This issue affects s2Member Pro: from n/a through 241114.

Affected:
up to 241216
Fixed in:
241216
Disclosed:
Dec 6, 2024

CVE-2024-51815 on NVD →

s2Member (Pro) <= 241114 - Unauthenticated Remote Code Execution

high

The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions (Pro) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 241114. This makes it possible for unauthenticated attackers to execute code on the server.

CVSS:
8.1
Affected:
up to 241114
Fixed in:
241216
Disclosed:
Dec 2, 2024

CVE-2024-51815 on NVD →

s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls &amp; Member Access Subscriptions [s2member] < 240325

unknown

[en] Improper Privilege Management vulnerability in WP Sharks s2Member Pro allows Privilege Escalation.This issue affects s2Member Pro: from n/a through 240315.

Affected:
up to 240325
Fixed in:
240325
Disclosed:
May 17, 2024

CVE-2024-31237 on NVD →

s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls &amp; Member Access Subscriptions [s2member] < 240315

unknown

[en] The s2Member – Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 230815 via the API. This makes it possible for unauthenticated attackers to see the content...

Affected:
up to 240315
Fixed in:
240315
Disclosed:
Apr 9, 2024

CVE-2024-0899 on NVD →

s2Member <= 240315 - Limited Privilege Escalation

critical

The s2Member plugin for WordPress is vulnerable to limited privilege escalation in versions up to, and including, 240315. This is due to insufficient controls during user registration. This makes it possible for unauthenticated attackers to register with higher than the default permissions.

CVSS:
9.1
Affected:
up to 240315
Fixed in:
240325
Disclosed:
Apr 5, 2024

CVE-2024-31237 on NVD →

s2Member – Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions <= 230815 - Information Exposure

medium

The s2Member – Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 230815 via the API. This makes it possible for unauthenticated attackers to see the contents of...

CVSS:
5.3
Affected:
up to 230815
Fixed in:
240315
Disclosed:
Mar 18, 2024

CVE-2024-0899 on NVD →

s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls &amp; Member Access Subscriptions [s2member] < 111220

unknown

[en] Cross-site scripting (XSS) vulnerability in the s2Member Pro plugin before 111220 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s2member_pro_authnet_checkout[coupon] parameter (aka Coupon Code field).

Affected:
up to 111220
Fixed in:
111220
Disclosed:
Mar 19, 2012

CVE-2011-5082 on NVD →

s2Member® Framework (Membership, Member Level Roles, Access Capabilities, PayPal Members) < 111220 - Cross-Site Scripting

high

Cross-site scripting (XSS) vulnerability in the s2Member Pro plugin before 111220 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s2member_pro_authnet_checkout[coupon] parameter (aka Coupon Code field).

CVSS:
7.2
Affected:
up to 111220
Fixed in:
111220
Disclosed:
Feb 12, 2012

CVE-2011-5082 on NVD →

s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls &amp; Member Access Subscriptions [s2member] < 241216

unknown
Affected:
up to 241216
Fixed in:
241216

CVE-2024-8326 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database