CVE-2026-15047 PUBLISHED

s2Member < 260805 - Contributor+ Stored XSS via Shortcode

Assigner: WPScan
Reserved: 08.07.2026 Published: 10.08.2026 Updated: 10.08.2026

The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside an inline script context, allowing users with contributor-level access to inject arbitrary JavaScript that executes when a viewer opens the post (stored XSS).

Product Status

Vendor Unknown
Product s2Member
Versions Default: unaffected
  • affected from 0 to 260805 (excl.)

Credits

  • Muni Nitish Kumar Yaddala finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE