Cross-Site Scripting Vulnerability in s2Member Pro by Cristián Lávaque
CVE-2025-26879
7.1HIGH
Key Information:
- Vendor
- Cristián Lávaque
- Status
- S2member Pro
- Vendor
- CVE Published:
- 3 March 2025
Summary
A vulnerability in s2Member Pro developed by Cristián Lávaque allows for reflected Cross-Site Scripting (XSS) attacks due to improper handling of input during web page generation. This issue affects all versions of s2Member Pro from n/a through 241216, enabling potential attackers to inject malicious scripts that can be executed in the context of the user’s browser, compromising user data and security. Website owners using this plugin should take immediate steps to update and patch their systems to mitigate the risk of exploitation.
Affected Version(s)
s2Member Pro <= 241216
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
0xd4rk5id3 (Patchstack Alliance)