Information Exposure Vulnerability in s2Member Plugin for WordPress
CVE-2024-0899

5.3MEDIUM

Summary

The s2Member plugin for WordPress, essential for managing memberships and content access, is exposed to a significant vulnerability. All versions up to and including 230815 allow unauthenticated attackers to access sensitive post and page content through the API. This flaw compromises user privacy and data security, enabling unauthorized views of otherwise restricted content.

Affected Version(s)

s2Member – Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions * <= 230815

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Francesco Carlucci
.