Beta

Report

s2Member <= 230815 is vulnerable to Information Exposure vulnerability

Unauthenticated
Published
2024-03-18

The s2Member – Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 230815 via the API. This makes it possible for unauthenticated attackers to see the contents of those posts and pages.

CVSS

Score:5.3

Severity:Medium

Version: 230815

There is a patch available in v240315 and we strongly recommend you update to this version as soon as possible.