s2Member <= 260804 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The s2Member plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 260804 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that w...
- CVSS:
- 6.4
- Affected:
- up to 260804
- Fixed in:
- 260805
- Disclosed:
- Aug 7, 2026
CVE-2026-15047 on NVD →
s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions [s2member] < 260101
unknown
[en] The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 's2Eot' shortcode in all versions up to, and including, 251005 due to insufficient input sanitization and output escap...
- Affected:
- up to 260101
- Fixed in:
- 260101
- Disclosed:
- Feb 19, 2026
CVE-2025-13732 on NVD →
s2Member <= 260127 - Unauthenticated Privilege Escalation via Account Takeover
critical
The s2Member plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 260127. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's...
- CVSS:
- 9.8
- Affected:
- up to 260127
- Fixed in:
- 260215
- Disclosed:
- Feb 18, 2026
CVE-2026-1994 on NVD →
s2Member <= 251005 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 's2Eot' shortcode in all versions up to, and including, 251005 due to insufficient input sanitization and output escaping....
- CVSS:
- 6.4
- Affected:
- up to 251005
- Fixed in:
- 260101
- Disclosed:
- Feb 18, 2026
CVE-2025-13732 on NVD →
s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions [s2member] <= 250701 (unfixed)
unknown
[en] Deserialization of Untrusted Data vulnerability in Cristián Lávaque s2Member s2member allows Object Injection.This issue affects s2Member: from n/a through <= 250701.
- Affected:
- up to 250701
- Fix:
- No patched version reported
- Disclosed:
- Nov 6, 2025
CVE-2025-58998 on NVD →
s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions [s2member] <= 250905 (unfixed)
unknown
[en] Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member.This issue affects s2Member: from n/a through <= 250905.
- Affected:
- up to 250905
- Fix:
- No patched version reported
- Disclosed:
- Oct 22, 2025
CVE-2025-62023 on NVD →
s2Member <= 250905 - Unauthenticated Remote Code Execution
critical
The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 250905. This makes it possible for unauthenticated attackers to execute code on the server.
- CVSS:
- 9.8
- Affected:
- up to 250905
- Fixed in:
- 251005
- Disclosed:
- Oct 1, 2025
CVE-2025-62023 on NVD →
s2Member <= 250701 - Unauthenticated PHP Object Injection
high
The s2Member plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 250701 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an...
- CVSS:
- 8.1
- Affected:
- up to 250701
- Fixed in:
- 250905
- Disclosed:
- Aug 21, 2025
CVE-2025-58998 on NVD →
s2Member <= 250419 - Authenticated (Administrator+) Local File Inclusion
high
The s2Member plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 250419 via the 'ws_plugin__s2member_log_file' parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arbitrary files on the server, allowing...
- CVSS:
- 7.2
- Affected:
- up to 250419
- Fixed in:
- 250424
- Disclosed:
- Apr 4, 2025
CVE-2025-32137 on NVD →
s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions [s2member] < 250424
unknown
[en] Relative Path Traversal vulnerability in Cristián Lávaque s2Member allows Path Traversal. This issue affects s2Member: from n/a through 250214.
- Affected:
- up to 250424
- Fixed in:
- 250424
- Disclosed:
- Apr 4, 2025
CVE-2025-32137 on NVD →
s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions [s2member] < 250214
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cristián Lávaque s2Member Pro allows Reflected XSS. This issue affects s2Member Pro: from n/a through 241216.
- Affected:
- up to 250214
- Fixed in:
- 250214
- Disclosed:
- Mar 3, 2025
CVE-2025-26879 on NVD →
s2Member Pro <= 241216 - Reflected Cross-Site Scripting
medium
The s2Member Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 241216 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully t...
- CVSS:
- 6.1
- Affected:
- up to 241216
- Fixed in:
- 250214
- Disclosed:
- Feb 22, 2025
CVE-2025-26879 on NVD →
s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions [s2member] < 250214
unknown
[en] The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 241114. This makes it...
- Affected:
- up to 250214
- Fixed in:
- 250214
- Disclosed:
- Feb 18, 2025
CVE-2024-11376 on NVD →
s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions <= 241216 - Reflected Cross-Site Scripting
medium
The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 241114. This makes it possi...
- CVSS:
- 6.1
- Affected:
- up to 241216
- Fixed in:
- 250214
- Disclosed:
- Feb 17, 2025
CVE-2024-11376 on NVD →
s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions <= 241114 - Authenticated (Contributor+) Sensitive Information Exposure
high
The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 241114 via the 'sc_get_details' function. This makes it possible for authenticated attackers, with...
- CVSS:
- 8.8
- Affected:
- up to 241114
- Fixed in:
- 241216
- Disclosed:
- Dec 16, 2024
CVE-2024-8326 on NVD →
s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions [s2member] < 241216
unknown
[en] Improper Control of Generation of Code ('Code Injection') vulnerability in WP Sharks s2Member Pro allows Code Injection.This issue affects s2Member Pro: from n/a through 241114.
- Affected:
- up to 241216
- Fixed in:
- 241216
- Disclosed:
- Dec 6, 2024
CVE-2024-51815 on NVD →
s2Member (Pro) <= 241114 - Unauthenticated Remote Code Execution
high
The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions (Pro) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 241114. This makes it possible for unauthenticated attackers to execute code on the server.
- CVSS:
- 8.1
- Affected:
- up to 241114
- Fixed in:
- 241216
- Disclosed:
- Dec 2, 2024
CVE-2024-51815 on NVD →
s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions [s2member] < 240325
unknown
[en] Improper Privilege Management vulnerability in WP Sharks s2Member Pro allows Privilege Escalation.This issue affects s2Member Pro: from n/a through 240315.
- Affected:
- up to 240325
- Fixed in:
- 240325
- Disclosed:
- May 17, 2024
CVE-2024-31237 on NVD →
s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions [s2member] < 240315
unknown
[en] The s2Member – Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 230815 via the API. This makes it possible for unauthenticated attackers to see the content...
- Affected:
- up to 240315
- Fixed in:
- 240315
- Disclosed:
- Apr 9, 2024
CVE-2024-0899 on NVD →
s2Member <= 240315 - Limited Privilege Escalation
critical
The s2Member plugin for WordPress is vulnerable to limited privilege escalation in versions up to, and including, 240315. This is due to insufficient controls during user registration. This makes it possible for unauthenticated attackers to register with higher than the default permissions.
- CVSS:
- 9.1
- Affected:
- up to 240315
- Fixed in:
- 240325
- Disclosed:
- Apr 5, 2024
CVE-2024-31237 on NVD →
s2Member – Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions <= 230815 - Information Exposure
medium
The s2Member – Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 230815 via the API. This makes it possible for unauthenticated attackers to see the contents of...
- CVSS:
- 5.3
- Affected:
- up to 230815
- Fixed in:
- 240315
- Disclosed:
- Mar 18, 2024
CVE-2024-0899 on NVD →
s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions [s2member] < 111220
unknown
[en] Cross-site scripting (XSS) vulnerability in the s2Member Pro plugin before 111220 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s2member_pro_authnet_checkout[coupon] parameter (aka Coupon Code field).
- Affected:
- up to 111220
- Fixed in:
- 111220
- Disclosed:
- Mar 19, 2012
CVE-2011-5082 on NVD →
s2Member® Framework (Membership, Member Level Roles, Access Capabilities, PayPal Members) < 111220 - Cross-Site Scripting
high
Cross-site scripting (XSS) vulnerability in the s2Member Pro plugin before 111220 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s2member_pro_authnet_checkout[coupon] parameter (aka Coupon Code field).
- CVSS:
- 7.2
- Affected:
- up to 111220
- Fixed in:
- 111220
- Disclosed:
- Feb 12, 2012
CVE-2011-5082 on NVD →
s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions [s2member] < 241216
unknown
- Affected:
- up to 241216
- Fixed in:
- 241216
CVE-2024-8326 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database