CVE-2025-62023: WordPress s2Member plugin <= 250905 - Remote Code Execution (RCE) vulnerability
Published Oct 22, 2025
·Updated
Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member.This issue affects s2Member: from n/a through <= 250905.
Affected Software
2 affected components
Cristián Lávaque s2Member<=250905
WordPress s2Member plugin<=250905
Event History
Oct 22, 2025
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-62023?
CVE-2025-62023 is considered a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2025-62023?
To fix CVE-2025-62023, update the s2Member plugin to a version higher than 250905.
3
What versions of s2Member are affected by CVE-2025-62023?
CVE-2025-62023 affects s2Member versions from n/a through 250905.
4
Can CVE-2025-62023 lead to a complete system compromise?
Yes, if exploited, CVE-2025-62023 can allow an attacker to execute arbitrary code, potentially compromising the entire system.
5
Is it safe to use s2Member plugin if I'm on a version above 250905 regarding CVE-2025-62023?
Yes, using a version above 250905 will mitigate the risks associated with CVE-2025-62023.