S2member is a WordPress membership and access-control plugin whose vulnerability profile centers on deserialization and input-validation issues characteristic of web-application plugins operating within a shared hosting environment. The recurring weakness classes—untrusted deserialization and cross-site scripting—reflect the plugin's role in handling user data and session state across WordPress sites. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by S2member over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-12562CRITICAL The s2Member Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 241216 via deserialization of untrusted input from the 's2member_p | Feb 15, 2025 | 9.8 | 29 | NO | NO |
CVE-2011-5082MEDIUM Cross-site scripting (XSS) vulnerability in the s2Member Pro plugin before 111220 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s2member_pro_ | Mar 19, 2012 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by S2member.
Media articles that mention a CVE ID that affects a product developed by S2member — matched by CVE ID, not by vendor name.