Local File Inclusion Vulnerability in s2Member Pro Plugin for WordPress
CVE-2024-12563
What is CVE-2024-12563?
The s2Member Pro plugin for WordPress poses a security risk due to a Local File Inclusion vulnerability. This flaw exists in all versions up to and including 250214 and allows authenticated attackers with contributor-level permissions or higher to include arbitrary files on the server via the 'template' attribute. This capability permits the execution of arbitrary PHP code, which may lead to access control bypass, sensitive data exposure, or unauthorized code execution. Website owners using this plugin should ensure timely updates and conduct security assessments to mitigate potential exploits.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
s2Member Pro * <= 250214
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved