Description
The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside an inline script context, allowing users with contributor-level access to inject arbitrary JavaScript that executes when a viewer opens the post (stored XSS).
Published: 2026-08-10
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The s2Member WordPress plugin, for any version prior to 260805, fails to escape several shortcode attributes before inserting them into an inline script block. Contributors can therefore inject arbitrary JavaScript that is stored in the post and executed when a viewer opens the post, leading to a stored XSS flaw.

Affected Systems

WordPress sites using the s2Member plugin with a version less than 260805 are affected. The vulnerability applies to all users with contributor or higher privileges who can add or edit posts containing shortcodes.

Risk and Exploitability

Based on the description, it is inferred that if a contributor inserts a malicious shortcode, the plugin will store the unescaped JavaScript and render it inside an inline script block, executing in the browsers of any visitor who opens the post. Consequently, an attacker with contributor privileges can compromise site visitors by injecting and storing code. The risk is significant for sites that expose sensitive data or rely on user authentication. No EPSS score is available and the vulnerability is not yet listed in the CISA KEV catalog, but the lack of input escaping and the inline script context make exploitation straightforward for authenticated users.

Generated by OpenCVE AI on August 10, 2026 at 07:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the s2Member plugin to version 260805 or later.
  • If an upgrade is not immediately possible, remove or disable the use of shortcodes that trigger the vulnerability and restrict contributor roles from inserting shortcodes.
  • Apply a Content Security Policy that limits inline scripts or blocks execution of injected JavaScript.

Generated by OpenCVE AI on August 10, 2026 at 07:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared S2member
S2member s2member
Wordpress
Wordpress wordpress
Vendors & Products S2member
S2member s2member
Wordpress
Wordpress wordpress

Mon, 10 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside an inline script context, allowing users with contributor-level access to inject arbitrary JavaScript that executes when a viewer opens the post (stored XSS).
Title s2Member < 260805 - Contributor+ Stored XSS via Shortcode
References

Subscriptions

S2member S2member
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-10T06:00:19.129Z

Reserved: 2026-07-08T12:46:11.998Z

Link: CVE-2026-15047

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T07:30:13Z

Weaknesses

No weakness.