WordPress Plugin Vulnerabilities

s2Member < 260805 - Contributor+ Stored XSS via Shortcode

Description

The plugin does not escape several shortcode attributes before outputting them inside an inline script context, allowing users with contributor-level access to inject arbitrary JavaScript that executes when a viewer opens the post (stored XSS).

Proof of Concept

Affects Plugins

Fixed in 260805

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Muni Nitish Kumar Yaddala
Submitter
Muni Nitish Kumar Yaddala
Verified
Yes

Timeline

Publicly Published
2026-08-07 (about 3 days ago)
Added
2026-08-07 (about 2 days ago)
Last Updated
2026-08-07 (about 2 days ago)

Other