VYPR

S2member Pro

by Wp Sharks

CVEs (3)

  • CVE-2024-12563HigMar 18, 2025
    risk 0.57cvss 8.8epss 0.01

    The s2Member Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 250214 via the 'template' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute…

  • CVE-2024-31237HigMay 17, 2024
    risk 0.49cvss 7.5epss 0.00

    Improper Privilege Management vulnerability in WP Sharks s2Member Pro allows Privilege Escalation.This issue affects s2Member Pro: from n/a through 240315.

  • CVE-2024-12562Feb 15, 2025
    risk 0.00cvss epss 0.01

    The s2Member Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 241216 via deserialization of untrusted input from the 's2member_pro_remote_op' vulnerable parameter. This makes it possible for unauthenticated attackers to inject…