Cross-Site Scripting Vulnerability in s2Member Pro by Cristián Lávaque
CVE-2025-26879
What is CVE-2025-26879?
A vulnerability in s2Member Pro developed by Cristián Lávaque allows for reflected Cross-Site Scripting (XSS) attacks due to improper handling of input during web page generation. This issue affects all versions of s2Member Pro from n/a through 241216, enabling potential attackers to inject malicious scripts that can be executed in the context of the user’s browser, compromising user data and security. Website owners using this plugin should take immediate steps to update and patch their systems to mitigate the risk of exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
s2Member Pro <= 241216
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved