Impact
The vulnerability in the s2Member plugin is an Improper Control of Generation of Code ('Code Injection') flaw (CWE‑94) that affects versions up to 250905. It allows an attacker to inject arbitrary PHP code, which can be executed on the host server, potentially leading to full compromise of the site and underlying infrastructure. The impact is functionally severe, granting full control over the website’s data, configuration, and hosting environment, thereby threatening confidentiality, integrity, and availability.
Affected Systems
The affected product is the s2Member plugin by Cristián Lávaque. All releases from the first available version up to and including version 250905 are vulnerable. No specific patched version is listed, but any release newer than 250905 is required to mitigate the issue. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 9 indicates high severity. The EPSS score is less than 1%, suggesting a low current exploitation probability, and the vulnerability is not listed in CISA KEV. Because the flaw is remote code execution via the plugin, the likely attack vector is a malicious HTTP request to the plugin’s entry points, implying remote exploitation without user interaction. The risk remains high if the vulnerable plugin remains active on any publicly accessible site.
OpenCVE Enrichment