Local File Inclusion Vulnerability in s2Member Pro Plugin for WordPress
CVE-2024-12563
8.8HIGH
What is CVE-2024-12563?
The s2Member Pro plugin for WordPress poses a security risk due to a Local File Inclusion vulnerability. This flaw exists in all versions up to and including 250214 and allows authenticated attackers with contributor-level permissions or higher to include arbitrary files on the server via the 'template' attribute. This capability permits the execution of arbitrary PHP code, which may lead to access control bypass, sensitive data exposure, or unauthorized code execution. Website owners using this plugin should ensure timely updates and conduct security assessments to mitigate potential exploits.
Affected Version(s)
s2Member Pro * <= 250214