First published: Tue Apr 09 2024(Updated: )
The s2Member – Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 230815 via the API. This makes it possible for unauthenticated attackers to see the contents of those posts and pages.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
s2Member | <=230815 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-0899 has a severity rating that indicates a significant risk of information exposure due to the vulnerability.
To fix CVE-2024-0899, update the s2Member plugin to the latest version beyond 230815.
All users of the s2Member plugin for WordPress running versions up to and including 230815 are affected by CVE-2024-0899.
CVE-2024-0899 is classified as an Information Exposure vulnerability.
Yes, CVE-2024-0899 allows unauthenticated attackers to exploit the vulnerability via the API.