The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside an inline script context, allowing users with contributor-level access to inject arbitrary JavaScript that executes when a viewer opens the post (stored XSS).
History

Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Mon, 10 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared S2member
S2member s2member
Wordpress
Wordpress wordpress
Vendors & Products S2member
S2member s2member
Wordpress
Wordpress wordpress

Mon, 10 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside an inline script context, allowing users with contributor-level access to inject arbitrary JavaScript that executes when a viewer opens the post (stored XSS).
Title s2Member < 260805 - Contributor+ Stored XSS via Shortcode
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2026-08-10T06:00:19.129Z

Updated: 2026-08-11T15:00:35.637Z

Reserved: 2026-07-08T12:46:11.998Z

Link: CVE-2026-15047

cve-icon Vulnrichment

Updated: 2026-08-11T15:00:00.417Z

cve-icon NVD

Status : Received

Published: 2026-08-10T07:16:47.493

Modified: 2026-08-11T16:17:29.553

Link: CVE-2026-15047

cve-icon Redhat

No data.