PT-2026-69347 · WordPress · S2Member

CVE-2026-15047

·

Published

2026-08-10

·

Updated

2026-08-11

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions s2Member WordPress plugin versions prior to 260805
Description The plugin fails to escape several shortcode attributes before they are output within an inline script context. This allows users with contributor-level access to perform a stored Cross-Site Scripting (XSS) attack by injecting arbitrary JavaScript that executes when a viewer opens the affected post.
Recommendations Update the s2Member WordPress plugin to version 260805 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15047

Affected Products

S2Member