First published: Mon Mar 19 2012(Updated: )
Cross-site scripting (XSS) vulnerability in the s2Member Pro plugin before 111220 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s2member_pro_authnet_checkout[coupon] parameter (aka Coupon Code field).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
s2Member | <=111216 | |
s2Member | =110604 | |
s2Member | =110605 | |
s2Member | =110606 | |
s2Member | =110617 | |
s2Member | =110620 | |
s2Member | =110708 | |
s2Member | =110709 | |
s2Member | =110710 | |
s2Member | =110731 | |
s2Member | =110812 | |
s2Member | =110815 | |
s2Member | =110912 | |
s2Member | =110913 | |
s2Member | =110915 | |
s2Member | =110926 | |
s2Member | =110927 | |
s2Member | =111002 | |
s2Member | =111003 | |
s2Member | =111011 | |
s2Member | =111017 | |
s2Member | =111029 | |
s2Member | =111105 | |
s2Member | =111206 | |
WordPress |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-5082 is classified as a medium severity cross-site scripting (XSS) vulnerability.
To fix CVE-2011-5082, you should update the s2Member Pro plugin to version 111220 or newer.
CVE-2011-5082 affects s2Member Pro versions prior to 111220 including 110604 through 111206.
CVE-2011-5082 affects WordPress installations using vulnerable versions of the s2Member Pro plugin.
CVE-2011-5082 can facilitate cross-site scripting attacks, allowing attackers to inject arbitrary web scripts.