Extension WordPress
Vulnérabilités s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions
Cette page rassemble les failles publiées pour s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions
12 fiches
s2Member <= 260127 – Unauthenticated Privilege Escalation via Account Takeover
The s2Member plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 260127. This is due to the plugin not properly validating a user's identity prior to updating their password.…
*-260127
260215
18/02/2026
s2Member <= 251005 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 's2Eot' shortcode in all versions up to, and including, 251005…
*-251005
260101
18/02/2026
s2Member <= 250905 – Unauthenticated Remote Code Execution
The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 250905. This makes it possible for…
*-250905
251005
01/10/2025
s2Member <= 250701 – Unauthenticated PHP Object Injection
The s2Member plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 250701 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP…
*-250701
250905
21/08/2025
s2Member <= 250419 – Authenticated (Administrator+) Local File Inclusion
The s2Member plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 250419 via the 'ws_plugin__s2member_log_file' parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute…
*-250419
250424
04/04/2025
s2Member Pro <= 241216 – Reflected Cross-Site Scripting
The s2Member Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 241216 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-241216
250214
22/02/2025
s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions <= 241216 – Reflected Cross-Site Scripting
The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in…
*-241216
250214
17/02/2025
s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions <= 241114 – Authenticated (Contributor+) Sensitive Information Exposure
The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 241114 via the 'sc_get_details' function. This…
*-241114
241216
16/12/2024
s2Member (Pro) <= 241114 – Unauthenticated Remote Code Execution
The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions (Pro) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 241114. This makes it possible…
*-241114
241216
02/12/2024
s2Member <= 240315 – Limited Privilege Escalation
The s2Member plugin for WordPress is vulnerable to limited privilege escalation in versions up to, and including, 240315. This is due to insufficient controls during user registration. This makes it possible for unauthenticated attackers to register with higher…
*-240315
240325
05/04/2024
s2Member – Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions <= 230815 – Information Exposure
The s2Member – Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 230815 via the API. This…
*-230815
240315
18/03/2024
s2Member® Framework (Membership, Member Level Roles, Access Capabilities, PayPal Members) < 111220 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the s2Member Pro plugin before 111220 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s2member_pro_authnet_checkout[coupon] parameter (aka Coupon Code field).
[*, 111220)
111220
12/02/2012
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.