CyberRota Analysis
AI-GeneratedThe s2Member WordPress plugin prior to version 260805 is vulnerable to stored cross-site scripting (XSS) due to insufficient escaping of shortcode attributes in inline scripts, allowing users with contributor-level access to inject malicious JavaScript. This vulnerability can lead to unauthorized script execution when a viewer accesses the affected post, potentially compromising user data and site integrity. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate the risk.
Original NVD Description
The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside an inline script context, allowing users with contributor-level access to inject arbitrary JavaScript that executes when a viewer opens the post (stored XSS).