WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions

❤️ Excellent membership plugin! Easy, quick, flexible. Monetize your site with memberships and subscriptions. Protect content instantly and securely.

13Reported vulnerabilities
9.8Highest CVSS score
260814Latest version
8,000+Active installs

What to do now

Update s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions to 260805 or later. 13 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 14, 2026 / Tested up to WordPress: 7.1 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2026-1994 Critical 9.8 0.4% 0 to 260127 (inclusive) 260215 February 19, 2026
CVE-2025-62023 Critical 9.8 0.4% 250905 and earlier 251005 October 1, 2025
CVE-2024-31237 Critical 9.1 0.4% 240315 and earlier 240325 April 5, 2024
CVE-2024-8326 High 8.8 0.6% 0 to 241114 (inclusive) 241216 December 17, 2024
CVE-2025-58998 High 8.1 0.5% 250701 and earlier 250905 August 21, 2025
CVE-2024-51815 High 8.1 0.5% 241114 and earlier 241216 December 2, 2024
CVE-2011-5082 High 7.2 1.9% Before 111220 111220 February 12, 2012
CVE-2025-32137 High 7.2 0.8% 250419 and earlier 250424 April 4, 2025
CVE-2025-13732 Medium 6.4 0.3% 0 to 251005 (inclusive) 260101 February 19, 2026
CVE-2026-15047 Medium 6.4 0.2% 260804 and earlier 260805 August 7, 2026
CVE-2025-26879 Medium 6.1 0.3% 241216 and earlier 250214 February 22, 2025
CVE-2024-11376 Medium 6.1 0.4% Before 250214 250214 February 18, 2025
CVE-2024-0899 Medium 5.3 0.6% 230815 and earlier 240315 March 18, 2024

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.