VYPR

S2member Pro

by WordPress

CVEs (4)

  • CVE-2024-12562CriFeb 15, 2025
    risk 0.64cvss 9.8epss 0.01

    The s2Member Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 241216 via deserialization of untrusted input from the 's2member_pro_remote_op' vulnerable parameter. This makes it possible for unauthenticated attackers to inject…

  • CVE-2024-12563HigMar 18, 2025
    risk 0.57cvss 8.8epss 0.01

    The s2Member Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 250214 via the 'template' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute…

  • CVE-2024-31237HigMay 17, 2024
    risk 0.49cvss 7.5epss 0.00

    Improper Privilege Management vulnerability in WP Sharks s2Member Pro allows Privilege Escalation.This issue affects s2Member Pro: from n/a through 240315.

  • CVE-2011-5082Mar 19, 2012
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in the s2Member Pro plugin before 111220 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s2member_pro_authnet_checkout[coupon] parameter (aka Coupon Code field).