Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cristián Lávaque s2Member s2member allows Reflected XSS.This issue affects s2Member: from n/a through <= 241216.
Published: 2025-03-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a classic Reflected XSS flaw caused by improper neutralization of input on a web page, identified as CWE-79. It allows an attacker to inject malicious scripts into the page that can be executed in the context of a victim’s browser, potentially leading to session hijacking, credential theft, or defacement. The impact is limited to confidentiality and integrity of user sessions and the integrity of web pages displayed to attackers’ victims, but it does not provide direct code execution or system compromise.

Affected Systems

The flaw affects the s2Member WordPress plugin produced by Cristián Lávaque. All versions from the earliest available release up through and including 241216 are vulnerable. No specific build or module variants are listed, so any instance of the plugin with a version number less than or equal to 241216 is potentially exposed.

Risk and Exploitability

The CVSS v3 score of 7.1 reflects a medium to high severity, and the EPSS score of less than 1% indicates a low but non‑zero likelihood that the flaw is actively exploited. The flaw is not listed in the CISA KEV catalog. The most likely attack vector is a reflected XSS attack via crafted URLs or input fields that the plugin fails to sanitize; an attacker can lure a user to a crafted link that injects malicious script. Proper isolation of user data or use of a web application firewall can mitigate typical exploitation paths.

Generated by OpenCVE AI on May 1, 2026 at 14:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the s2Member plugin to the latest released version that removes the vulnerability.
  • Configure WordPress or a security plugin to ensure all user input is properly sanitized and filtered before rendering.
  • Deploy a web application firewall to detect and block reflected XSS payloads or malicious script execution attempts.

Generated by OpenCVE AI on May 1, 2026 at 14:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5614 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cristián Lávaque s2Member Pro allows Reflected XSS. This issue affects s2Member Pro: from n/a through 241216.
History

Wed, 29 Apr 2026 10:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cristián Lávaque s2Member Pro allows Reflected XSS. This issue affects s2Member Pro: from n/a through 241216. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cristián Lávaque s2Member s2member allows Reflected XSS.This issue affects s2Member: from n/a through <= 241216.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cristián Lávaque s2Member Pro allows Reflected XSS. This issue affects s2Member Pro: from n/a through 241216.
Title WordPress s2Member Plugin <= 241216 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-29T09:51:54.688Z

Reserved: 2025-02-17T11:50:22.449Z

Link: CVE-2025-26879

cve-icon Vulnrichment

Updated: 2025-03-03T14:34:02.752Z

cve-icon NVD

Status : Deferred

Published: 2025-03-03T14:15:56.213

Modified: 2026-04-29T10:16:42.507

Link: CVE-2025-26879

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T14:15:20Z

Weaknesses