CVE-2025-58998: WordPress s2Member Plugin <= 250701 - PHP Object Injection Vulnerability
Published Nov 6, 2025
·Updated
Deserialization of Untrusted Data vulnerability in Cristián Lávaque s2Member s2member allows Object Injection.This issue affects s2Member: from n/a through <= 250701.
Affected Software
2 affected components
Cristián Lávaque s2Member<=250701
WordPress s2Member plugin<=250701
Event History
Nov 6, 2025
CVE Published
via MITRE·03:54 PM
Data Sourced
via MITRE·03:54 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-58998?
CVE-2025-58998 is classified as a high-severity vulnerability due to its potential for object injection and exploitation.
2
How do I fix CVE-2025-58998?
To fix CVE-2025-58998, update s2Member to the latest version that exceeds 250701.
3
What type of vulnerability is CVE-2025-58998?
CVE-2025-58998 is a deserialization of untrusted data vulnerability that allows for object injection.
4
Which versions of s2Member are affected by CVE-2025-58998?
CVE-2025-58998 affects all versions of s2Member up to and including 250701.
5
Who is the vendor for CVE-2025-58998?
The vendor for CVE-2025-58998 is Cristián Lávaque, the creator of the s2Member plugin.